[PATCH] Fix out of bounds memory access in res_nquerydomain
Jeff Law
law@redhat.com
Wed Feb 29 06:41:00 GMT 2012
This was spotted by Serge Pavlovsky
/*
* Check for trailing '.';
* copy without '.' if present.
*/
n = strlen(name);
if (n >= MAXDNAME) {
RES_SET_H_ERRNO(statp, NO_RECOVERY);
return (-1);
}
n--;
if (n >= 0 && name[n] == '.') {
N is of type size_t, and thus unsigned. GCC will quite sensibly
eliminate the n >= 0 check. Thus if NAME was an empty string, we will
read from name[-1].
It looks like this has been broken since 1999 or so when these bits were
converted to use strncpy & friends rather than bcopy and MAXDNAME
instead of sizeof (nbuf).
ISTM the easiest fix is to decrement N immediately after the call to
strlen and twiddle MAXDNAME test to use MAXDNAME - 1. If N wraps, that
test will be true and we'll return a reasonable error.
The n >= 0 test is pointless and should just be deleted.
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: patch
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20120229/b284efa1/attachment.ksh>
More information about the Libc-alpha
mailing list