git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] Fix buggy ref recording

From
Petr Baudis <pasky@suse.cz>
Date
Sep 22, 2006, 23:08 UTC
Message-ID
<20060922230845.GB8259@pasky.or.cz>
In-Reply-To
<20060919205554.GA8259@pasky.or.cz>

Dear diary, on Tue, Sep 19, 2006 at 10:55:54PM CEST, I got a letter where Petr Baudis <pasky@suse.cz> said that...

Show 10 quoted lines
> Dear diary, on Thu, Sep 14, 2006 at 07:14:47PM CEST, I got a letter
> where Linus Torvalds <torvalds@osdl.org> said that...
> > +	ref_file = git_path(ref);
> 
> You slip...
> You fall...
> *BLAMMMM!!!*
> 
> Cloning a repository with '%s' tag over HTTP now dumps core nicely, and
> I guess this kind of bugs tends to be exploitable.
And since just reporting it did not magically result in a fix... ;-)
-8<-

There is a format string vulnerability introduced with the packed refs file format.

Signed-off-by: Petr Baudis <pasky@suse.cz>
---
 refs.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/refs.c b/refs.c
index 40f16af..5fdf9c4 100644
--- a/refs.c
+++ b/refs.c
@@ -472,7 +472,7 @@ static struct ref_lock *lock_ref_sha1_ba

 	lock->ref_name = xstrdup(ref);
 	lock->log_file = xstrdup(git_path("logs/%s", ref));
-	ref_file = git_path(ref);
+	ref_file = git_path("%s", ref);
 	lock->force_write = lstat(ref_file, &st) && errno == ENOENT;

 	if (safe_create_leading_directories(ref_file))
-- 
				Petr "Pasky" Baudis
Stuff: http://pasky.or.cz/
#!/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj
$/=unpack('H*',$_);$_=`echo 16dio\U$k"SK$/SM$n\EsN0p[lN*1
lK[d2%Sa2/d0$^Ixp"|dc`;s/\W//g;$_=pack('H*',/((..)*)$/)
Previous: Phil RichardsNext: Junio C Hamano
Message 5 of 8 in “Enable the packed refs file format”
  1. Linus TorvaldsSep 14, 2006
  2. Petr BaudisSep 19, 2006
  3. Linus TorvaldsSep 19, 2006
  4. Phil RichardsSep 20, 2006
  5. Fix buggy ref recordingPetr Baudis, Sep 22, 2006
  6. Junio C HamanoSep 23, 2006
  7. Petr BaudisSep 23, 2006
  8. pack-refs: fix git_path() usage.Junio C Hamano, Sep 23, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.