Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 13 Mar 2010 13:13:51 -0800
From:      Garrett Cooper <yanefbsd@gmail.com>
To:        Bruce Cran <brucec@freebsd.org>
Cc:        svn-src-head@freebsd.org, svn-src-all@freebsd.org, src-committers@freebsd.org
Subject:   Re: svn commit: r205118 - head/sbin/sysctl
Message-ID:  <7d6fde3d1003131313l3559b6dbt1566fb23be150408@mail.gmail.com>
In-Reply-To: <201003131108.o2DB8vmu001454@svn.freebsd.org>
References:  <201003131108.o2DB8vmu001454@svn.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, Mar 13, 2010 at 3:08 AM, Bruce Cran <brucec@freebsd.org> wrote:
> Author: brucec
> Date: Sat Mar 13 11:08:57 2010
> New Revision: 205118
> URL: http://svn.freebsd.org/changeset/base/205118
>
> Log:
> =A0Free the memory allocated via strdup.
>
> =A0PR: =A0 =A0 =A0 =A0 =A0 bin/113881
> =A0Submitted by: Alexander Drozdov =A0dzal_mail mtu-net.ru
> =A0Approved by: =A0rrs (mentor)
> =A0MFC after: =A0 =A01 week
>
> Modified:
> =A0head/sbin/sysctl/sysctl.c
>
> Modified: head/sbin/sysctl/sysctl.c
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D
> --- head/sbin/sysctl/sysctl.c =A0 Sat Mar 13 11:06:47 2010 =A0 =A0 =A0 =
=A0(r205117)
> +++ head/sbin/sysctl/sysctl.c =A0 Sat Mar 13 11:08:57 2010 =A0 =A0 =A0 =
=A0(r205118)
> @@ -382,6 +382,7 @@ S_timeval(int l2, void *p)
> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0if (*p2 =3D=3D '\n')
> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0*p2 =3D '\0';
> =A0 =A0 =A0 =A0fputs(p1, stdout);
> + =A0 =A0 =A0 free(p1);
> =A0 =A0 =A0 =A0return (0);
> =A0}

    strdup(3) can fail in that section of code, thus the fputs(3)
could segfault:

[gcooper@bayonetta ~]$ cat foo.c
#include <string.h>
#include <stdio.h>

int main(void) {
	char *foo =3D NULL;
	fputs(foo, stdout);
	free(foo);
	return 0;
}
[gcooper@bayonetta ~]$ gcc -o foo foo.c
[gcooper@bayonetta ~]$ ./foo
Segmentation fault: 11 (core dumped)

    Could a...

    if (p1 =3D=3D NULL)

    ... be added before the fputs(3) please?

Thanks,
-Garrett



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?7d6fde3d1003131313l3559b6dbt1566fb23be150408>