[PATCH] Harden put*ent functions against data injection [BZ #18724]

Florian Weimer fweimer@redhat.com
Mon Jul 27 15:19:00 GMT 2015


This patch addresses a “Bobby Tables” issue in the put*ent functions and
the getent program, similar to one of the recent libuser issues.

I believe this is just hardening because users of the put*ent functions
already have appropriate checks before they call these functions, so
this is definitely post-freeze material.

Tested on x86_64-redhat-linux-gnu.  Okay to commit after master reopens?

-- 
Florian Weimer / Red Hat Product Security
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Harden-putpwent-putgrent-putspent-putspent-against-i.patch
Type: text/x-patch
Size: 40817 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20150727/ed9fa67e/attachment.bin>


More information about the Libc-alpha mailing list