Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 46126 Details for
Bug 73943
net-fs/samba CAN-2004-1154: Integer overflow could lead to remote code execution in Samba 2.x, 3.0.x <= 3.0.9 (Vendor-Sec)
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
files/samba-3.0.9-util.c-bitmap.c-4120.patch
samba-3.0.9-util.c-bitpmap.c-4120.patch (text/plain), 1.83 KB, created by
Christian Andreetta (RETIRED)
on 2004-12-16 07:32:14 UTC
(
hide
)
Description:
files/samba-3.0.9-util.c-bitmap.c-4120.patch
Filename:
MIME Type:
Creator:
Christian Andreetta (RETIRED)
Created:
2004-12-16 07:32:14 UTC
Size:
1.83 KB
patch
obsolete
>Index: branches/SAMBA_3_0/source/lib/util.c >=================================================================== >--- branches/SAMBA_3_0/source/lib/util.c (revision 4119) >+++ branches/SAMBA_3_0/source/lib/util.c (revision 4120) >@@ -867,9 +867,7 @@ > void *malloc_(size_t size) > { > #undef malloc >- /* If we don't add an amount here the glibc memset seems to write >- one byte over. */ >- return malloc(size+16); >+ return malloc(size); > #define malloc(s) __ERROR_DONT_USE_MALLOC_DIRECTLY > } > >@@ -880,9 +878,7 @@ > static void *calloc_(size_t count, size_t size) > { > #undef calloc >- /* If we don't add an amount here the glibc memset seems to write >- one byte over. */ >- return calloc(count+1, size); >+ return calloc(count, size); > #define calloc(n,s) __ERROR_DONT_USE_CALLOC_DIRECTLY > } > >@@ -893,9 +889,7 @@ > static void *realloc_(void *ptr, size_t size) > { > #undef realloc >- /* If we don't add an amount here the glibc memset seems to write >- one byte over. */ >- return realloc(ptr, size+16); >+ return realloc(ptr, size); > #define realloc(p,s) __ERROR_DONT_USE_RELLOC_DIRECTLY > } > >Index: branches/SAMBA_3_0/source/lib/bitmap.c >=================================================================== >--- branches/SAMBA_3_0/source/lib/bitmap.c (revision 4119) >+++ branches/SAMBA_3_0/source/lib/bitmap.c (revision 4120) >@@ -41,7 +41,7 @@ > return NULL; > } > >- memset(bm->b, 0, sizeof(bm->b[0])*(n+31)/32); >+ memset(bm->b, 0, sizeof(uint32)*((n+31)/32)); > > return bm; > } >@@ -78,7 +78,7 @@ > return NULL; > } > >- memset(bm->b, 0, sizeof(bm->b[0])*(n+31)/32); >+ memset(bm->b, 0, sizeof(uint32)*((n+31)/32)); > > return bm; > } >@@ -92,7 +92,7 @@ > int count = MIN(dst->n, src->n); > > SMB_ASSERT(dst->b != src->b); >- memcpy(dst->b, src->b, sizeof(dst->b[0])*(count+31)/32); >+ memcpy(dst->b, src->b, sizeof(uint32)*((count+31)/32)); > > return count; > }
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 73943
:
45624
|
45681
|
45682
|
46112
|
46113
|
46125
| 46126