Uploaded image for project: 'ROOT'
  1. ROOT
  2. ROOT-8322

Possible buffer overflow in /net/rpdutils

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: High
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 6.08/00
    • Component/s: Other
    • Labels:
      None
    • Environment:

      No environment

      Description

      In /net/rpdutils/src/rpdutils.cxx at Line 2034:
      {{ SPrintf(gUserAllow[mth[jm]], gUserIgnLen[mth[jm]], "%s %d",
      gUserAllow[mth[jm]], (int)pw->pw_uid);}}

      The second argument is probably wrong. The buffer size is stored in gUserAlwLen ant not in gUserIgnLen. That looks like a buffer overflow to me.

        Attachments

          Activity

            People

            Assignee:
            ganis Gerardo Ganis
            Reporter:
            f059a5b78ba1a1ee2863 Raphael Isemann
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Actual Start: