[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
jobserver_fds->list buffer overflow
From: |
Ken Takusagawa |
Subject: |
jobserver_fds->list buffer overflow |
Date: |
Mon, 8 Jan 2007 22:26:11 -0500 |
In main.c we have
jobserver_fds->list[0] = xmalloc ((sizeof ("1024")*2)+1);
sprintf (jobserver_fds->list[0], "%d,%d", job_fds[0], job_fds[1]);
Shouldn't xmalloc get a "+2" instead of "+1"? 1 for the comma, and
one for the null terminator?
--ken
- jobserver_fds->list buffer overflow,
Ken Takusagawa <=