Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 72248 Details for
Bug 111573
net-ftp/ftpd: remote hole in linux-ftpd-ssl (CVE-2005-3524)
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
fixes BOF in reply() in ftpd.c ssl version - vsprintf to vsnprintf
linux-ftpd-0.17+ssl-0.3-overflowpatch.diff (text/plain), 532 bytes, created by
James Longstreet
on 2005-11-05 15:16:43 UTC
(
hide
)
Description:
fixes BOF in reply() in ftpd.c ssl version - vsprintf to vsnprintf
Filename:
MIME Type:
Creator:
James Longstreet
Created:
2005-11-05 15:16:43 UTC
Size:
532 bytes
patch
obsolete
>--- linux-ftpd-0.17/ftpd/ftpd.c 2005-11-05 17:04:53.000000000 -0600 >+++ linux-ftpd-0.17-patched/ftpd/ftpd.c 2005-11-05 17:11:54.000000000 -0600 >@@ -2082,9 +2082,9 @@ > va_start(ap); > #endif > #ifdef USE_SSL >- /* assemble the output into a buffer */ >+ /* assemble the output into a buffer, checking for length*/ > sprintf(outputbuf,"%d ",n); >- vsprintf(outputbuf+strlen(outputbuf),fmt,ap); >+ vsnprintf(outputbuf+strlen(outputbuf),2048-(strlen(outputbuf) + 3),fmt,ap); > strcat(outputbuf,"\r\n"); > > if (ssl_debug_flag)
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 111573
: 72248 |
72306