NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: bin/52432: /etc/dumpdates format egregious
The following reply was made to PR bin/52432; it has been noted by GNATS.
From: christos%zoulas.com@localhost (Christos Zoulas)
To: gnats-bugs%NetBSD.org@localhost, gnats-admin%netbsd.org@localhost, netbsd-bugs%netbsd.org@localhost
Cc:
Subject: Re: bin/52432: /etc/dumpdates format egregious
Date: Wed, 26 Jul 2017 22:55:37 -0400
On Jul 26, 9:30pm, greywolf%starwolf.com@localhost (greywolf%starwolf.com@localhost) wrote:
-- Subject: bin/52432: /etc/dumpdates format egregious
Because %s can cause a buffer overflow. The better solution is to stop
using scanf... This started with:
https://gnats.netbsd.org/cgi-bin/query-pr-single.pl?number=50434
Unfortunately DUMP{IN,OUT}FMT is the "api".
christos
Home |
Main Index |
Thread Index |
Old Index