Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 23 Dec 2015 18:24:40 +0000 (UTC)
From:      Jilles Tjoelker <jilles@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-10@freebsd.org
Subject:   svn commit: r292664 - stable/10/bin/sh
Message-ID:  <201512231824.tBNIOeie027454@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: jilles
Date: Wed Dec 23 18:24:40 2015
New Revision: 292664
URL: https://svnweb.freebsd.org/changeset/base/292664

Log:
  MFC r292360: sh: Fix use-after-free when attempting to modify a read-only
  variable.
  
  Reported by:	bapt

Modified:
  stable/10/bin/sh/var.c
Directory Properties:
  stable/10/   (props changed)

Modified: stable/10/bin/sh/var.c
==============================================================================
--- stable/10/bin/sh/var.c	Wed Dec 23 17:54:19 2015	(r292663)
+++ stable/10/bin/sh/var.c	Wed Dec 23 18:24:40 2015	(r292664)
@@ -328,7 +328,7 @@ setvareq(char *s, int flags)
 		if (vp->flags & VREADONLY) {
 			if ((flags & (VTEXTFIXED|VSTACK)) == 0)
 				ckfree(s);
-			error("%.*s: is read only", vp->name_len, s);
+			error("%.*s: is read only", vp->name_len, vp->text);
 		}
 		if (flags & VNOSET) {
 			if ((flags & (VTEXTFIXED|VSTACK)) == 0)



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201512231824.tBNIOeie027454>