From owner-svn-src-all@FreeBSD.ORG Sun Nov 9 14:38:25 2008 Return-Path: Delivered-To: svn-src-all@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B090A106567B; Sun, 9 Nov 2008 14:38:25 +0000 (UTC) (envelope-from kostikbel@gmail.com) Received: from mail.terabit.net.ua (mail.terabit.net.ua [195.137.202.147]) by mx1.freebsd.org (Postfix) with ESMTP id 471568FC14; Sun, 9 Nov 2008 14:38:25 +0000 (UTC) (envelope-from kostikbel@gmail.com) Received: from skuns.zoral.com.ua ([91.193.166.194] helo=mail.zoral.com.ua) by mail.terabit.net.ua with esmtps (TLSv1:AES256-SHA:256) (Exim 4.63 (FreeBSD)) (envelope-from ) id 1KzBQl-0003HM-5z; Sun, 09 Nov 2008 16:38:23 +0200 Received: from deviant.kiev.zoral.com.ua (root@deviant.kiev.zoral.com.ua [10.1.1.148]) by mail.zoral.com.ua (8.14.2/8.14.2) with ESMTP id mA9EcKSq053172 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun, 9 Nov 2008 16:38:20 +0200 (EET) (envelope-from kostikbel@gmail.com) Received: from deviant.kiev.zoral.com.ua (kostik@localhost [127.0.0.1]) by deviant.kiev.zoral.com.ua (8.14.3/8.14.3) with ESMTP id mA9EcKr3074052; Sun, 9 Nov 2008 16:38:20 +0200 (EET) (envelope-from kostikbel@gmail.com) Received: (from kostik@localhost) by deviant.kiev.zoral.com.ua (8.14.3/8.14.3/Submit) id mA9EcJA6074051; Sun, 9 Nov 2008 16:38:19 +0200 (EET) (envelope-from kostikbel@gmail.com) X-Authentication-Warning: deviant.kiev.zoral.com.ua: kostik set sender to kostikbel@gmail.com using -f Date: Sun, 9 Nov 2008 16:38:19 +0200 From: Kostik Belousov To: Matteo Riondato Message-ID: <20081109143819.GO18100@deviant.kiev.zoral.com.ua> References: <200811090644.mA96ira1032670@svn.freebsd.org> <20081109132026.GL18100@deviant.kiev.zoral.com.ua> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="hA47Z5c7pMOLFxYj" Content-Disposition: inline In-Reply-To: <20081109132026.GL18100@deviant.kiev.zoral.com.ua> User-Agent: Mutt/1.4.2.3i X-Virus-Scanned: ClamAV version 0.93.3, clamav-milter version 0.93.3 on skuns.kiev.zoral.com.ua X-Virus-Status: Clean X-Spam-Status: No, score=-4.4 required=5.0 tests=ALL_TRUSTED,AWL,BAYES_00 autolearn=ham version=3.2.5 X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on skuns.kiev.zoral.com.ua X-Virus-Scanned: mail.terabit.net.ua 1KzBQl-0003HM-5z 57a501e97732323432956a453b2bb400 X-Terabit: YES Cc: svn-src-head@freebsd.org, svn-src-all@freebsd.org, src-committers@freebsd.org Subject: Re: svn commit: r184779 - head/usr.sbin/cron/crontab X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 09 Nov 2008 14:38:25 -0000 --hA47Z5c7pMOLFxYj Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Nov 09, 2008 at 03:20:26PM +0200, Kostik Belousov wrote: > On Sun, Nov 09, 2008 at 06:44:53AM +0000, Matteo Riondato wrote: > > Author: matteo > > Date: Sun Nov 9 06:44:53 2008 > > New Revision: 184779 > > URL: http://svn.freebsd.org/changeset/base/184779 > >=20 > > Log: > > Be paranoid and use snprintf > > =20 > > PR: bin/122137 > > Submitted by: Steven Kreuzer > > MFC after: 3 days > >=20 > > Modified: > > head/usr.sbin/cron/crontab/crontab.c > >=20 > > Modified: head/usr.sbin/cron/crontab/crontab.c > > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D > > --- head/usr.sbin/cron/crontab/crontab.c Sun Nov 9 01:53:06 2008 (r184= 778) > > +++ head/usr.sbin/cron/crontab/crontab.c Sun Nov 9 06:44:53 2008 (r184= 779) > > @@ -263,7 +263,7 @@ list_cmd() { > > FILE *f; > > =20 > > log_it(RealUser, Pid, "LIST", User); > > - (void) sprintf(n, CRON_TAB(User)); > > + (void) snprintf(n, sizeof(n), CRON_TAB(User)); > This note is probably also about paranoia instead of exploitable bug. > I think that it is better to use %s format explicitely instead of > expecting no '%' in the CRON_TAB(User). Please, ignore this. I should have looked at the actual code. --hA47Z5c7pMOLFxYj Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (FreeBSD) iEYEARECAAYFAkkW9dsACgkQC3+MBN1Mb4gG/ACfcYQ3yoHewHoYFlrDkrcPGfeV oWEAoN3/Q004t/j0zoJ6oNwuFu5wiqI5 =hS4L -----END PGP SIGNATURE----- --hA47Z5c7pMOLFxYj--