Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 2 Mar 2021 18:43:42 GMT
From:      Edward Tomasz Napierala <trasz@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org
Subject:   git: a3576b620707 - stable/13 - libc: fix buffer overrun in getrpcport(3)
Message-ID:  <202103021843.122IhgMb018739@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch stable/13 has been updated by trasz:

URL: https://cgit.FreeBSD.org/src/commit/?id=a3576b6207074ba5182be253c26af72f8fb51759

commit a3576b6207074ba5182be253c26af72f8fb51759
Author:     Edward Tomasz Napierala <trasz@FreeBSD.org>
AuthorDate: 2021-01-31 21:41:55 +0000
Commit:     Edward Tomasz Napierala <trasz@FreeBSD.org>
CommitDate: 2021-03-02 18:43:26 +0000

    libc: fix buffer overrun in getrpcport(3)
    
    Reviewed By:    markj
    Sponsored by:   NetApp, Inc.
    Sponsored by:   Klara, Inc.
    Differential Revision: https://reviews.freebsd.org/D27332
    
    (cherry picked from commit 5299d64b2b9f7a25e423ef1785d9402a0ef198d3)
---
 lib/libc/rpc/getrpcport.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/lib/libc/rpc/getrpcport.c b/lib/libc/rpc/getrpcport.c
index 2b2d459c8887..4abc9a0c16af 100644
--- a/lib/libc/rpc/getrpcport.c
+++ b/lib/libc/rpc/getrpcport.c
@@ -62,14 +62,14 @@ getrpcport(char *host, int prognum, int versnum, int proto)
 
 	assert(host != NULL);
 
-	if ((hp = gethostbyname(host)) == NULL)
+	if ((hp = gethostbyname2(host, AF_INET)) == NULL)
 		return (0);
 	memset(&addr, 0, sizeof(addr));
 	addr.sin_len = sizeof(struct sockaddr_in);
 	addr.sin_family = AF_INET;
 	addr.sin_port =  0;
-	if (hp->h_length > addr.sin_len)
-		hp->h_length = addr.sin_len;
+	if (hp->h_length > sizeof(addr.sin_addr.s_addr))
+		hp->h_length = sizeof(addr.sin_addr.s_addr);
 	memcpy(&addr.sin_addr.s_addr, hp->h_addr, (size_t)hp->h_length);
 	/* Inconsistent interfaces need casts! :-( */
 	return (pmap_getport(&addr, (u_long)prognum, (u_long)versnum, 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202103021843.122IhgMb018739>