Re: iproute2: tc: potential buffer overflow
From: Stephen Hemminger <stephen@networkplumber.org>
Date: 2019-08-31 15:37:57
From: Stephen Hemminger <stephen@networkplumber.org>
Date: 2019-08-31 15:37:57
On Sat, 31 Aug 2019 15:13:27 +0200 (CEST) [off-list ref] wrote:
Hi, there are two potentially dangerous calls of strcpy function in the program "tc". In the attachment is a patch that fixes this issue. Tomas
This looks correct. Please fix with strlcpy() instead; that is clearer. Plus you can use XT_EXTENSION_MAX_NAMELEN here (optional).