git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3] Fix buffer overflow in config parser

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Apr 17, 2009, 13:16 UTC
Message-ID
<alpine.DEB.1.00.0904171516400.6675@intel-tinevez-2-302>
In-Reply-To
<200904171405.48269.thomas.jarosch@intra2net.com>
Hi,
On Fri, 17 Apr 2009, Thomas Jarosch wrote:
Show 12 quoted lines
> When interpreting a config value, the config parser reads in 1+ space
> character(s) and puts -one- space character in the buffer as soon as
> the first non-space character is encountered (if not inside quotes).
> 
> Unfortunately the buffer size check lacks the extra space character
> which gets inserted at the next non-space character, resulting in
> a crash with a specially crafted config entry.
> 
> The unit test now uses Java to compile a platform independent
> .NET framework to output the test string in C# :o) Read:
> Thanks to Johannes Sixt for the correct printf call
> which replaces the perl invocation.
LOL!

Thanks, Dscho

Previous: Thomas Jarosch
Message 10 of 10 in “Fix buffer overflow in config parser”
  1. Fix buffer overflow in config parserThomas Jarosch, Apr 14, 2009
  2. Johannes SchindelinApr 14, 2009
  3. Thomas JaroschApr 14, 2009
  4. Jeff KingApr 15, 2009
  5. Jeff KingApr 15, 2009
  6. Junio C HamanoApr 14, 2009
  7. Johannes SixtApr 15, 2009
  8. Johannes SixtApr 15, 2009
  9. Fix buffer overflow in config parserThomas Jarosch, Apr 17, 2009
  10. Johannes SchindelinApr 17, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.