From owner-cvs-lib Mon Dec 16 09:33:02 1996 Return-Path: Received: (from root@localhost) by freefall.freebsd.org (8.8.4/8.8.4) id JAA19466 for cvs-lib-outgoing; Mon, 16 Dec 1996 09:33:02 -0800 (PST) Received: (from joerg@localhost) by freefall.freebsd.org (8.8.4/8.8.4) id JAA19458; Mon, 16 Dec 1996 09:33:01 -0800 (PST) Date: Mon, 16 Dec 1996 09:33:01 -0800 (PST) From: Joerg Wunsch Message-Id: <199612161733.JAA19458@freefall.freebsd.org> To: CVS-committers, cvs-all, cvs-lib Subject: cvs commit: src/lib/libc/locale collate.c setrunelocale.c Sender: owner-cvs-lib@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk joerg 96/12/16 09:33:00 Modified: lib/libc/locale collate.c setrunelocale.c Log: Fix yet another buffer overflow. :-( Vulnerable: all programs that use setlocale(LC_COLLATE), setlocale(LC_CTYPE), or setlocale(LC_ALL). The only setuid/setgid binary i've found for this is w(1). Should go into 2.2. Revision Changes Path 1.10 +3 -5 src/lib/libc/locale/collate.c 1.5 +2 -4 src/lib/libc/locale/setrunelocale.c