Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 5 Dec 2012 13:56:53 +0000 (UTC)
From:      Eitan Adler <eadler@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org
Subject:   svn commit: r243897 - head/usr.sbin/pw
Message-ID:  <201212051356.qB5DurOH068385@svn.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: eadler
Date: Wed Dec  5 13:56:52 2012
New Revision: 243897
URL: http://svnweb.freebsd.org/changeset/base/243897

Log:
  Avoid overflowing the file buffer
  
  Submitted by:	db
  Approved by:	cperciva
  MFC after:	2 weeks

Modified:
  head/usr.sbin/pw/rm_r.c

Modified: head/usr.sbin/pw/rm_r.c
==============================================================================
--- head/usr.sbin/pw/rm_r.c	Wed Dec  5 13:56:49 2012	(r243896)
+++ head/usr.sbin/pw/rm_r.c	Wed Dec  5 13:56:52 2012	(r243897)
@@ -52,7 +52,7 @@ rm_r(char const * dir, uid_t uid)
 
 		while ((e = readdir(d)) != NULL) {
 			if (strcmp(e->d_name, ".") != 0 && strcmp(e->d_name, "..") != 0) {
-				sprintf(file, "%s/%s", dir, e->d_name);
+				snprintf(file, sizeof(file), "%s/%s", dir, e->d_name);
 				if (lstat(file, &st) == 0) {	/* Need symlinks, not
 								 * linked file */
 					if (S_ISDIR(st.st_mode))	/* Directory - recurse */



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201212051356.qB5DurOH068385>