svn commit: r292360 - head/bin/sh

Jilles Tjoelker jilles at FreeBSD.org
Wed Dec 16 20:33:48 UTC 2015


Author: jilles
Date: Wed Dec 16 20:33:47 2015
New Revision: 292360
URL: https://svnweb.freebsd.org/changeset/base/292360

Log:
  sh: Fix use-after-free when attempting to modify a read-only variable.
  
  Reported by:	bapt
  MFC after:	1 week

Modified:
  head/bin/sh/var.c

Modified: head/bin/sh/var.c
==============================================================================
--- head/bin/sh/var.c	Wed Dec 16 20:17:57 2015	(r292359)
+++ head/bin/sh/var.c	Wed Dec 16 20:33:47 2015	(r292360)
@@ -330,7 +330,7 @@ setvareq(char *s, int flags)
 		if (vp->flags & VREADONLY) {
 			if ((flags & (VTEXTFIXED|VSTACK)) == 0)
 				ckfree(s);
-			error("%.*s: is read only", vp->name_len, s);
+			error("%.*s: is read only", vp->name_len, vp->text);
 		}
 		if (flags & VNOSET) {
 			if ((flags & (VTEXTFIXED|VSTACK)) == 0)


More information about the svn-src-head mailing list