Re: Buffer overflow in disklabel

From: Sebastian Ssmoller <sebastian.ssmoller_at_web.de>
Date: 20 Apr 2003 10:16:23 +0200
Hi,
I attached a patch for that problem. Can someone have a look at it?

But one thing is still unclear to me: Why do we need 8k buffer for the
disk name? 

seb

Am Son, 2003-04-20 um 05.23 schrieb Kris Kennaway:
> Run the following under /bin/sh (not tcsh, which - still! - has a bug
> that causes the command to hang tcsh):
> 
> # disklabel `perl -e 'print "a"x51200'`
> Segmentation fault (core dumped)
> 
> The responsible code is:
> 
>         dkname = argv[0];
>         if (dkname[0] != '/') {
>                 (void)sprintf(np, "%s%s%c", _PATH_DEV, dkname, 'a' + RAW_PART);
>                 specname = np;
>                 np += strlen(specname) + 1;
>         } else
>                 specname = dkname;
>         f = open(specname, op == READ ? O_RDONLY : O_RDWR);
>         if (f < 0 && errno == ENOENT && dkname[0] != '/') {
>                 (void)sprintf(specname, "%s%s", _PATH_DEV, dkname);
>                 np = namebuf + strlen(specname) + 1;
>                 f = open(specname, op == READ ? O_RDONLY : O_RDWR);
>         }
> 
> i.e. overflowing an 8k buffer.  Does anyone feel like fixing it?
> 
> Kris
Received on Sat Apr 19 2003 - 23:15:45 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:04 UTC