From owner-cvs-usrbin Sun Jul 14 17:57:37 1996 Return-Path: owner-cvs-usrbin Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id RAA23222 for cvs-usrbin-outgoing; Sun, 14 Jul 1996 17:57:37 -0700 (PDT) Received: from irz301.inf.tu-dresden.de (irz301.inf.tu-dresden.de [141.76.1.11]) by freefall.freebsd.org (8.7.5/8.7.3) with SMTP id RAA22047; Sun, 14 Jul 1996 17:51:21 -0700 (PDT) Received: from sax.sax.de by irz301.inf.tu-dresden.de (8.6.12/8.6.12-s1) with ESMTP id CAA00217; Mon, 15 Jul 1996 02:50:42 +0200 Received: (from uucp@localhost) by sax.sax.de (8.6.12/8.6.12-s1) with UUCP id CAA28803; Mon, 15 Jul 1996 02:50:42 +0200 Received: (from j@localhost) by uriah.heep.sax.de (8.7.5/8.6.9) id CAA13659; Mon, 15 Jul 1996 02:42:23 +0200 (MET DST) From: J Wunsch Message-Id: <199607150042.CAA13659@uriah.heep.sax.de> Subject: Re: cvs commit: src/usr.bin/rdist defs.h docmd.c expand.c lookup.c server.c To: bde@zeta.org.au (Bruce Evans) Date: Mon, 15 Jul 1996 02:42:22 +0200 (MET DST) Cc: pst@shockwave.com, thorpej@nas.nasa.gov, CVS-committers@freefall.freebsd.org, cvs-all@freefall.freebsd.org, cvs-usrbin@freefall.freebsd.org, nate@freefall.freebsd.org, wosch@cs.tu-berlin.de Reply-To: joerg_wunsch@uriah.heep.sax.de (Joerg Wunsch) In-Reply-To: <199607142351.JAA10509@godzilla.zeta.org.au> from Bruce Evans at "Jul 15, 96 09:51:26 am" X-Phone: +49-351-2012 669 X-PGP-Fingerprint: DC 47 E6 E4 FF A6 E9 8F 93 21 E0 7D F9 12 D6 4E X-Mailer: ELM [version 2.4ME+ PL17 (25)] MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-cvs-usrbin@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk As Bruce Evans wrote: > > > Should we disable sprintf() for sgid/suid programs? > > Why stop there? Convert all strcpy()s to snprintf()s. Convert all > pointers to arrays. Implement array bounds checking. Actually use > array bounds checking. !-) Use Pascal. -- cheers, J"org joerg_wunsch@uriah.heep.sax.de -- http://www.sax.de/~joerg/ -- NIC: JW11-RIPE Never trust an operating system you don't have sources for. ;-)