sanitize(): avoid strlen() to check string for NUL termination

The strlen() function can easiliy go out of bounds.  Use memchr()
instead, we have the max buffer len as argument anyway.

Also fix call to sanitize() which used wrong length.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2021-03-18 18:23:50 +01:00
parent d9993860cb
commit 74d715243c
2 changed files with 2 additions and 2 deletions
+1 -1
View File
@@ -617,7 +617,7 @@ int svc_parse_jobstr(char *str, size_t len, int (*found)(svc_t *), int (not_foun
char *ptr;
_d("Got token:'%s'", input);
token = sanitize(input, len);
token = sanitize(input, strlen(input) + 1);
if (!token) {
_d("Sanitation of token:'%s' failed", input);
goto next;
+1 -1
View File
@@ -193,7 +193,7 @@ char *sanitize(char *arg, size_t len)
regex_t preg;
int rc;
if (strlen(arg) > len)
if (!memchr(arg, 0, len))
return NULL;
if (regcomp(&preg, regex, REG_ICASE | REG_EXTENDED))