Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 9 Nov 2008 15:20:26 +0200
From:      Kostik Belousov <kostikbel@gmail.com>
To:        Matteo Riondato <matteo@freebsd.org>
Cc:        svn-src-head@freebsd.org, svn-src-all@freebsd.org, src-committers@freebsd.org
Subject:   Re: svn commit: r184779 - head/usr.sbin/cron/crontab
Message-ID:  <20081109132026.GL18100@deviant.kiev.zoral.com.ua>
In-Reply-To: <200811090644.mA96ira1032670@svn.freebsd.org>
References:  <200811090644.mA96ira1032670@svn.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--EyugWz6C5819Q3pC
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sun, Nov 09, 2008 at 06:44:53AM +0000, Matteo Riondato wrote:
> Author: matteo
> Date: Sun Nov  9 06:44:53 2008
> New Revision: 184779
> URL: http://svn.freebsd.org/changeset/base/184779
>=20
> Log:
>   Be paranoid and use snprintf
>  =20
>   PR:		bin/122137
>   Submitted by:	Steven Kreuzer <skreuzer@exit2shell.com>
>   MFC after:	3 days
>=20
> Modified:
>   head/usr.sbin/cron/crontab/crontab.c
>=20
> Modified: head/usr.sbin/cron/crontab/crontab.c
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D
> --- head/usr.sbin/cron/crontab/crontab.c	Sun Nov  9 01:53:06 2008	(r18477=
8)
> +++ head/usr.sbin/cron/crontab/crontab.c	Sun Nov  9 06:44:53 2008	(r18477=
9)
> @@ -263,7 +263,7 @@ list_cmd() {
>  	FILE	*f;
> =20
>  	log_it(RealUser, Pid, "LIST", User);
> -	(void) sprintf(n, CRON_TAB(User));
> +	(void) snprintf(n, sizeof(n), CRON_TAB(User));
This note is probably also about paranoia instead of exploitable bug.
I think that it is better to use %s format explicitely instead of
expecting no '%' in the CRON_TAB(User).

>  	if (!(f =3D fopen(n, "r"))) {
>  		if (errno =3D=3D ENOENT)
>  			errx(ERROR_EXIT, "no crontab for %s", User);
> @@ -293,7 +293,7 @@ delete_cmd() {
>  	}
> =20
>  	log_it(RealUser, Pid, "DELETE", User);
> -	(void) sprintf(n, CRON_TAB(User));
> +	(void) snprintf(n, sizeof(n), CRON_TAB(User));
>  	if (unlink(n)) {
>  		if (errno =3D=3D ENOENT)
>  			errx(ERROR_EXIT, "no crontab for %s", User);
> @@ -327,7 +327,7 @@ edit_cmd() {
>  	char		new_md5[MD5_SIZE];
> =20
>  	log_it(RealUser, Pid, "BEGIN EDIT", User);
> -	(void) sprintf(n, CRON_TAB(User));
> +	(void) snprintf(n, sizeof(n), CRON_TAB(User));
>  	if (!(f =3D fopen(n, "r"))) {
>  		if (errno !=3D ENOENT)
>  			err(ERROR_EXIT, "%s", n);
> @@ -337,7 +337,7 @@ edit_cmd() {
>  	}
> =20
>  	um =3D umask(077);
> -	(void) sprintf(Filename, "/tmp/crontab.XXXXXXXXXX");
> +	(void) snprintf(Filename, sizeof(Filename), "/tmp/crontab.XXXXXXXXXX");
>  	if ((t =3D mkstemp(Filename)) =3D=3D -1) {
>  		warn("%s", Filename);
>  		(void) umask(um);
> @@ -504,8 +504,8 @@ replace_cmd() {
>  		return (-2);
>  	}
> =20
> -	(void) sprintf(n, "tmp.%d", Pid);
> -	(void) sprintf(tn, CRON_TAB(n));
> +	(void) snprintf(n, sizeof(n), "tmp.%d", Pid);
> +	(void) snprintf(tn, sizeof(n), CRON_TAB(n));
>  	if (!(tmp =3D fopen(tn, "w+"))) {
>  		warn("%s", tn);
>  		return (-2);
> @@ -592,7 +592,7 @@ replace_cmd() {
>  		return (-2);
>  	}
> =20
> -	(void) sprintf(n, CRON_TAB(User));
> +	(void) snprintf(n, sizeof(n), CRON_TAB(User));
>  	if (rename(tn, n)) {
>  		warn("error renaming %s to %s", tn, n);
>  		unlink(tn);

--EyugWz6C5819Q3pC
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (FreeBSD)

iEYEARECAAYFAkkW45oACgkQC3+MBN1Mb4gfYQCg5TMAnQ+cJEhlagqffYeSSLn9
qyMAn1eJYaBBWg8z9rIKQqOkyk0sxfBk
=XRk+
-----END PGP SIGNATURE-----

--EyugWz6C5819Q3pC--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20081109132026.GL18100>