Thread (3 messages) 3 messages, 2 authors, 2019-09-07

Re: iproute2: tc: potential buffer overflow

From: Stephen Hemminger <stephen@networkplumber.org>
Date: 2019-08-31 15:37:57

On Sat, 31 Aug 2019 15:13:27 +0200 (CEST)
[off-list ref] wrote:
Hi,

there are two potentially dangerous calls of strcpy function in the program "tc". In the attachment is a patch that fixes this issue.

Tomas
This looks correct.

Please fix with strlcpy() instead; that is clearer.
Plus you can use XT_EXTENSION_MAX_NAMELEN here (optional).
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help