Date: Fri, 6 May 2005 02:48:21 +0000 (UTC) From: Colin Percival <cperciva@FreeBSD.org> To: src-committers@FreeBSD.org, cvs-src@FreeBSD.org, cvs-all@FreeBSD.org Subject: cvs commit: src/sys/kern subr_bus.c subr_rman.c vfs_subr.c src/sys/net if_mib.c src/sys/netinet ip_divert.c raw_ip.c udp_usrreq.c Message-ID: <200505060248.j462mL0k009905@repoman.freebsd.org>
next in thread | raw e-mail | index | archive | help
cperciva 2005-05-06 02:48:21 UTC FreeBSD src repository Modified files: sys/kern subr_bus.c subr_rman.c vfs_subr.c sys/net if_mib.c sys/netinet ip_divert.c raw_ip.c udp_usrreq.c Log: If we are going to 1. Copy a NULL-terminated string into a fixed-length buffer, and 2. copyout that buffer to userland, we really ought to 0. Zero the entire buffer first. Security: FreeBSD-SA-05:08.kmem Revision Changes Path 1.182 +1 -0 src/sys/kern/subr_bus.c 1.43 +2 -0 src/sys/kern/subr_rman.c 1.624 +3 -0 src/sys/kern/vfs_subr.c 1.15 +1 -0 src/sys/net/if_mib.c 1.112 +1 -0 src/sys/netinet/ip_divert.c 1.149 +1 -0 src/sys/netinet/raw_ip.c 1.174 +1 -0 src/sys/netinet/udp_usrreq.c
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200505060248.j462mL0k009905>