*BSD News Article 75964


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!news.rmit.EDU.AU!news.unimelb.EDU.AU!munnari.OZ.AU!news.ecn.uoknor.edu!news.wildstar.net!newsfeed.direct.ca!hunter.premier.net!news-res.gsl.net!news.gsl.net!news.mathworks.com!fu-berlin.de!main.Germany.EU.net!Dortmund.Germany.EU.net!interface-business.de!usenet
From: j@ida.interface-business.de (J Wunsch)
Newsgroups: comp.unix.bsd.netbsd.misc
Subject: Re: List of OpenBSD changes
Date: 12 Aug 1996 09:51:57 GMT
Organization: interface business GmbH, Dresden
Lines: 26
Message-ID: <4umurt$ic4@innocence.interface-business.de>
References: <DERAADT.96Aug8144209@zeus.theos.com> <4ufqap$44i@jan.et.byu.edu>
  <DERAADT.96Aug9113040@zeus.theos.com> <v6lofo6lju.fsf@kechara.flame.org>
  <4uljtk$jb0@redstone.interpath.net> <DERAADT.96Aug11183115@zeus.theos.com>
Reply-To: joerg_wunsch@interface-business.de (Joerg Wunsch)
NNTP-Posting-Host: ida.interface-business.de
X-Newsreader: knews 0.9.6
X-Phone: +49-351-31809-14
X-Fax: +49-351-3361187
X-PGP-Fingerprint: DC 47 E6 E4 FF A6 E9 8F  93 21 E0 7D F9 12 D6 4E

deraadt@theos.com (Theo de Raadt) wrote:

> ----------------------------
> revision 1.4
> date: 1996/08/08 07:58:07;  author: joerg;  state: Exp;  lines: +3 -2
> Fix a potential buffer overflow condition.
> 
> Submitted by:	Somebody on -hackers, ooops, i've already deleted that mail

> --- 72,80 ----
>   {
>   	struct lmc_stat	sbuf;
>   
> + 	sbuf.name[MAXLKMNAME - 1] = '\0'; /* In case strncpy limits the string. */
>   	if (modname != NULL)
> ! 		strncpy(sbuf.name, modname, MAXLKMNAME - 1);
>   
>   	sbuf.id = modnum;

Btw., MAXLKMNAME should better be ``sizeof sbuf.name''.  (Yes, i'm the
same `joerg' as you see above in the log message... :)

-- 
J"org Wunsch					       Unix support engineer
joerg_wunsch@interface-business.de       http://www.interface-business.de/~j