view tests/ref/sp5x/sp5x_problem.avi.md5 @ 35394:7bad316da87a

stream ftp: Pass full buffer size to snprintf Previously the buffer size was always passed as one less than the underlying buffer's size. This is not using the underlying buffer to its full potential according to the C99 standard. The last byte of the buffers were never used. No vulnerabilities should have been caused by this mistake because the strings stored in the buffers were zero terminated at all times. Neither were out-of-array writes nor reads possible.
author al
date Mon, 26 Nov 2012 23:36:00 +0000
parents f6cce8c4ea66
children
line wrap: on
line source

e7b40770471a66c631624eb74b86d79e frame00000000
991a503a53506ddccc4d57269ff16a15 frame00000001
255b8f514aed4bda9fa82813134be086 frame00000002
4049f5d77c8869f7576ef66b734f0869 frame00000003
ab7ca9bd95a1291f8e3348046677c52f frame00000004
a2803ecdd82fd8a18b78618ca3794d18 frame00000005
e999dbc00f52c400a194312fa78a6f2a frame00000006
28138d4eb330ecbf084618544260b630 frame00000007
6a38bb8822b88236417901aedbe32f73 frame00000008
2184a44436946eef36f3225b15df3072 frame00000009