mirror of
https://github.com/troglobit/finit.git
synced 2026-10-09 16:50:59 +07:00
sanitize(): avoid strlen() to check string for NUL termination
The strlen() function can easiliy go out of bounds. Use memchr() instead, we have the max buffer len as argument anyway. Also fix call to sanitize() which used wrong length. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
@@ -617,7 +617,7 @@ int svc_parse_jobstr(char *str, size_t len, int (*found)(svc_t *), int (not_foun
|
||||
char *ptr;
|
||||
|
||||
_d("Got token:'%s'", input);
|
||||
token = sanitize(input, len);
|
||||
token = sanitize(input, strlen(input) + 1);
|
||||
if (!token) {
|
||||
_d("Sanitation of token:'%s' failed", input);
|
||||
goto next;
|
||||
|
||||
+1
-1
@@ -193,7 +193,7 @@ char *sanitize(char *arg, size_t len)
|
||||
regex_t preg;
|
||||
int rc;
|
||||
|
||||
if (strlen(arg) > len)
|
||||
if (!memchr(arg, 0, len))
|
||||
return NULL;
|
||||
|
||||
if (regcomp(&preg, regex, REG_ICASE | REG_EXTENDED))
|
||||
|
||||
Reference in New Issue
Block a user