git/list[1] front-page[2] threads[3] people[4] search[5] about
 

minor problems in git.c

From
RWRobert Watson <robert.oo.watson@gmail.com>
Date
Dec 1, 2005, 12:00 UTC
Message-ID
<72499e3b0512010400i1de76ed2la22cd745f811007f@mail.gmail.com>
Hi,
There are some minor problems in git.c:
(1) potential buffer overrun.
        strncat(&git_command[len], "/git-", sizeof(git_command) - len);
        len += 5;
        strncat(&git_command[len], argv[i], sizeof(git_command) - len);

The first line will write one byte ('\0') beyond the end of git_command, when sizeof(git_command) - len == 5.

The second line increase len by 5, without regarding how many bytes are written in the first line. It is possible to make len greater than sizeof(git_command), therefore make the third argument of the third line underflow, allowing almost any number of bytes from argv[1] to be copied.

(2) environ
int main(int argc, char **argv, char **envp)
{
  ...
  execve(git_command, &argv[i], envp);
  ...
}

I am wondering whether the global variable "environ" could change when you do setenv. Would it be clear by using the "environ" as the third argument of evecve()?

(3) printf("Failed to run command '%s': %s\n", git_command, strerror(errno)); should go to stderr?

Regards, Robertoo

Next: Alex Riesen
Message 1 of 6 in “minor problems in git.c”
  1. Robert WatsonDec 1, 2005
  2. Alex RiesenDec 1, 2005
  3. Sven VerdoolaegeDec 1, 2005
  4. Alex RiesenDec 1, 2005
  5. Junio C HamanoDec 2, 2005
  6. Alex RiesenDec 2, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.