openbsd-ports/databases/gnats/patches/patch-gnats_mk_auth_c
brad 9e8ecfb2f4 Fix some security issues with gnats.
Some additional fixes from millert@
sprintf -> snprintf
str{cat,cpy} -> strl{cat,cpy}

http://marc.theaimsgroup.com/?l=bugtraq&m=105638591907836&w=2

ok naddy@
2003-08-25 23:33:56 +00:00

13 lines
575 B
Plaintext

$OpenBSD: patch-gnats_mk_auth_c,v 1.1 2003/08/25 23:35:06 brad Exp $
--- gnats/mk_auth.c.orig Thu Nov 5 12:54:10 1998
+++ gnats/mk_auth.c Wed Jul 2 13:23:13 2003
@@ -140,7 +140,7 @@ krb_mk_auth(options, ticket, service, in
#ifdef ATHENA_COMPAT
/* this is only for compatibility with old servers */
if (options & KOPT_DO_OLDSTYLE) {
- (void) sprintf(buf->dat,"%d ",ticket->length);
+ (void) snprintf(buf->dat, sizeof(buf->dat), "%d ", ticket->length);
(void) write(fd, buf, strlen(buf));
(void) write(fd, (char *) ticket->dat, ticket->length);
return(rem);