Re: [PATCH] Fix buffer overflow in config parser
- From
Markus Heidelberg <markus.heidelberg@web.de>
- Date
- Apr 8, 2009, 23:15 UTC
- Message-ID
- <200904090115.17609.markus.heidelberg@web.de>
- In-Reply-To
- <200904090058.42751.markus.heidelberg@web.de>
Markus Heidelberg, 09.04.2009:
Show 23 quoted lines
> Thomas Jarosch, 09.04.2009:
> > Hello together,
> >
> > attached is a small patch to fix a buffer overflow in config.c.
> > Patch is against git master's HEAD.
> >
> > I didn't send this one inline as I wanted to
> > preserve the 1024+ byte long line.
>
> You could send the patch inline and attach the example config.
>
> > diff --git a/config.c b/config.c
> > index b76fe4c..a9c67e8 100644
> > --- a/config.c
> > +++ b/config.c
> > @@ -72,7 +72,7 @@ static char *parse_value(void)
> > }
> > }
> > if (space) {
> > - if (len)
> > + if (len && len < sizeof(value)-1)
> > value[len++] = ' ';
> > space = 0;Eh, or maybe better add a "continue;" here, so that only one char per loop is read.
> > }