REDHAT-BUG-903466: Low severity suse coreutils vulnerability
It was reported [1] that the join command suffered from a segfault when processing input streams that contained extremely long strings when used with the -i switch. This flaw is due to the inclusion of the coreutils-i18n.patch.
SUSE has fixed this by fixing the patch. The changes can be seen here [2]. (There is probably e better place to get the patch, but I don't know where).
[1] https://bugzilla.novell.com/showbug.cgi?id=798541 [2] https://build.opensuse.org/request/show/149348#diffheadlinecoreutils-i18n-patchdiffaction0submit019
Statement:
(none)
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-903466?
The severity of REDHAT-BUG-903466 is classified as moderate due to the potential for segfaults when handling long strings.
How do I fix REDHAT-BUG-903466?
To fix REDHAT-BUG-903466, update your SUSE coreutils with the patched version that resolves the segfault issue.
What software is affected by REDHAT-BUG-903466?
REDHAT-BUG-903466 affects the SUSE coreutils package when using the join command with the -i switch.
What is the nature of the issue described in REDHAT-BUG-903466?
The issue in REDHAT-BUG-903466 involves a segmentation fault occurring in the join command due to extremely long input strings.
Has REDHAT-BUG-903466 been addressed by SUSE?
Yes, SUSE has addressed REDHAT-BUG-903466 by fixing the coreutils-i18n.patch that caused the problem.