e1c9b28667
supplied area of PATH_MAX+2 (buffer as well as buffer2). A tampered environment variable can be used to modify program flow. Way too many functions handle a return value of NULL for wexpandpath improperly, resulting in segfaults (and maybe other problems). To prove the existance of these issues: The improper parsing of environment variables can lead to expansion of path names that were not intended to be expanded. patch from Tobias Stoeckmann |
||
---|---|---|
.. | ||
patch-configure | ||
patch-src_wmspec_c | ||
patch-util_Makefile_in | ||
patch-util_wmaker_inst_in | ||
patch-WindowMaker_Defaults_WindowMaker_in | ||
patch-WindowMaker_Makefile_in | ||
patch-WindowMaker_menu | ||
patch-WindowMaker_plmenu | ||
patch-WINGs_findfile_c | ||
patch-WINGs_Makefile_in | ||
patch-WINGs_string_c | ||
patch-WINGs_wapplication_c | ||
patch-WINGs_wwindow_c | ||
patch-WPrefs_app_Menu_c | ||
patch-WPrefs_app_Paths_c | ||
patch-wrlib_Makefile_in |