Re: pspp - cve-2017-10791 - cve-2017-10792

2017-07-04 Thread Ben Pfaff
I applied fixes for both of these bugs to the PSPP repository, as the following commits. The fixes will be in the next PSPP release. commit 41c6f5447941e5d36d0554ba874671649353752f Author: Ben Pfaff Date: Tue Jul 4 12:58:55 2017 -0400 sys-file-reader: Fix integer overflows in

Re: Bug#866890: pspp - cve-2017-10791 - cve-2017-10792

2017-07-04 Thread Ben Pfaff
The attribution of the problem to the hash function is probably wrong, since that function is purely combinatorial logic, but the report as a whole is right because the attachment in the bug report at https://bugzilla.redhat.com/show_bug.cgi?id=1467004 does cause pspp-convert to assert-fail. I'm l