Change in ...libosmocore[master]: vty/vty.c: fix vty_read(): prevent further heap-buffer overrun
gerrit-no-reply at lists.osmocom.org
Tue Jul 30 16:47:46 UTC 2019
neels has posted comments on this change. ( https://gerrit.osmocom.org/c/libosmocore/+/14973 )
Change subject: vty/vty.c: fix vty_read(): prevent further heap-buffer overrun
Patch Set 3:
PS3, Line 1420: vty->buf[vty->length] = '\0';
While this might be correct, I wonder if there is a better place for this.
Usually I would expect stuff written to vty->buf and some range checks and assignment to vty->length right before this. Reading this here seems out of context: I don't see any vty->buf or vty->length used in this function. Where is the vty->buf filled with vty->length nr of characters?
If there is no single place like that, maybe it would make sense to put this nul termination into vty_execute()?
To view, visit https://gerrit.osmocom.org/c/libosmocore/+/14973
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings
Gerrit-Owner: Vadim Yanitskiy <axilirator at gmail.com>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: Vadim Yanitskiy <axilirator at gmail.com>
Gerrit-Reviewer: laforge <laforge at gnumonks.org>
Gerrit-Reviewer: pespin <pespin at sysmocom.de>
Gerrit-CC: neels <nhofmeyr at sysmocom.de>
Gerrit-Comment-Date: Tue, 30 Jul 2019 16:47:46 +0000
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the gerrit-log