This is the mail archive of the
glibc-bugs@sourceware.org
mailing list for the glibc project.
[Bug libc/23347] overflow at realpath()
- From: "ldv at sourceware dot org" <sourceware-bugzilla at sourceware dot org>
- To: glibc-bugs at sourceware dot org
- Date: Wed, 27 Jun 2018 18:19:39 +0000
- Subject: [Bug libc/23347] overflow at realpath()
- Auto-submitted: auto-generated
- References: <bug-23347-131@http.sourceware.org/bugzilla/>
https://sourceware.org/bugzilla/show_bug.cgi?id=23347
--- Comment #1 from Dmitry V. Levin <ldv at sourceware dot org> ---
(In reply to Dhiraj from comment #0)
> At file /io/tst-getcwd-abspath.c line number 46 which is,
Please note this is a test for #22679.
> cwd = realpath (".", NULL);
>
> This function does not protect against buffer overflows,
There are no buffers to overflow in the cited code.
> and some implementations can overflow internally such as (CWE-120/CWE-785!).
Please note that you have reached the GNU libc bugzilla.
> Ensure that the destination buffer is at least of size MAXPATHLEN, andto
> protect against implementation problems, the input argument should also be
> checked to ensure it is no larger than MAXPATHLEN.
Please elaborate.
--
You are receiving this mail because:
You are on the CC list for the bug.