svn commit: r191351 - in stable/7/contrib/ntp: . ntpq
Colin Percival
cperciva at FreeBSD.org
Tue Apr 21 10:49:41 UTC 2009
Author: cperciva
Date: Tue Apr 21 10:49:40 2009
New Revision: 191351
URL: http://svn.freebsd.org/changeset/base/191351
Log:
MFH r191302: Fix a buffer overflow.
For reasons of stack alignment, it does not appear that this is exploitable
on any systems FreeBSD runs on, so this will not be getting a security
advisory.
Approved by: re (kib)
Modified:
stable/7/contrib/ntp/ (props changed)
stable/7/contrib/ntp/ntpq/ntpq.c
Modified: stable/7/contrib/ntp/ntpq/ntpq.c
==============================================================================
--- stable/7/contrib/ntp/ntpq/ntpq.c Tue Apr 21 09:55:17 2009 (r191350)
+++ stable/7/contrib/ntp/ntpq/ntpq.c Tue Apr 21 10:49:40 2009 (r191351)
@@ -3185,9 +3185,9 @@ cookedprint(
if (!decodeuint(value, &uval))
output_raw = '?';
else {
- char b[10];
+ char b[12];
- (void) sprintf(b, "%03lo", uval);
+ (void) snprintf(b, sizeof(b), "%03lo", uval);
output(fp, name, b);
}
break;
More information about the svn-src-stable-7
mailing list