Re: [PATCH v3] Fix buffer overflow in config parser
- From
Johannes Schindelin <johannes.schindelin@gmx.de>
- Date
- Apr 17, 2009, 13:16 UTC
- Message-ID
- <alpine.DEB.1.00.0904171516400.6675@intel-tinevez-2-302>
- In-Reply-To
- <200904171405.48269.thomas.jarosch@intra2net.com>
Hi,
On Fri, 17 Apr 2009, Thomas Jarosch wrote:
Show 12 quoted lines
> When interpreting a config value, the config parser reads in 1+ space > character(s) and puts -one- space character in the buffer as soon as > the first non-space character is encountered (if not inside quotes). > > Unfortunately the buffer size check lacks the extra space character > which gets inserted at the next non-space character, resulting in > a crash with a specially crafted config entry. > > The unit test now uses Java to compile a platform independent > .NET framework to output the test string in C# :o) Read: > Thanks to Johannes Sixt for the correct printf call > which replaces the perl invocation.
LOL!
Thanks, Dscho