From owner-freebsd-bugs@FreeBSD.ORG Thu Sep 11 02:50:10 2003 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8724B16A4BF for ; Thu, 11 Sep 2003 02:50:10 -0700 (PDT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4437143FDF for ; Thu, 11 Sep 2003 02:50:09 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.12.9/8.12.9) with ESMTP id h8B9o9Up036951 for ; Thu, 11 Sep 2003 02:50:09 -0700 (PDT) (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.12.9/8.12.9/Submit) id h8B9o9oW036950; Thu, 11 Sep 2003 02:50:09 -0700 (PDT) Resent-Date: Thu, 11 Sep 2003 02:50:09 -0700 (PDT) Resent-Message-Id: <200309110950.h8B9o9oW036950@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Igor Truszkowski Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1E9E416A4BF for ; Thu, 11 Sep 2003 02:43:58 -0700 (PDT) Received: from escargot.linux.qx.pl (FreeBSD.rzepaknet.us [213.216.79.99]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4645543F85 for ; Thu, 11 Sep 2003 02:43:56 -0700 (PDT) (envelope-from igor@linux.qx.pl) Received: from igor by escargot.linux.qx.pl with local (Exim 4.22) id 19xNzn-0002FV-Nh for FreeBSD-gnats-submit@freebsd.org; Thu, 11 Sep 2003 11:44:11 +0200 Message-Id: Date: Thu, 11 Sep 2003 11:44:11 +0200 From: Igor Truszkowski To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Subject: bin/56696: atacontrol core dump (sscanf on unintialized pointer) X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Igor Truszkowski List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 11 Sep 2003 09:50:10 -0000 >Number: 56696 >Category: bin >Synopsis: atacontrol core dump (sscanf on unintialized pointer) >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Thu Sep 11 02:50:07 PDT 2003 >Closed-Date: >Last-Modified: >Originator: Igor Truszkowski >Release: FreeBSD 4.8-STABLE i386 >Organization: >Environment: System: FreeBSD escargot.linux.qx.pl 4.8-STABLE FreeBSD 4.8-STABLE #0: Tue Aug 5 13:24:45 CEST 2003 igor@escargot.truszkowski.one.pl:/vol1/obj/vol1/src/sys/ESCARGOT i386 Probably all architectures, tested on 4.8-STABLE and current RELENG_4 (4.9-PRERELEASE) on i386 arch. >Description: atacontrol in create mode (atacontrol create) does not check whether argv[2] and argv[3] are initialized before performing sscanf() on these pointers. >How-To-Repeat: just run `atacontrol create` or `atacontrol create RAID1` without additional arguments. >Fix: Problem is located near lines #306 and #320 in atacontrol.c. >Release-Note: >Audit-Trail: >Unformatted: