From: Jeff King <peff@peff.net>
To: git@vger.kernel.org
Cc: Erik Faye-Lund <kusmabite@gmail.com>, Junio C Hamano <gitster@pobox.com>
Subject: [PATCH 1/7] imap-send: avoid buffer overflow
Date: Thu, 8 Dec 2011 03:23:17 -0500 [thread overview]
Message-ID: <20111208082317.GA26409@sigill.intra.peff.net> (raw)
In-Reply-To: <20111208082118.GA1507@sigill.intra.peff.net>
We format the password prompt in an 80-character static
buffer. It contains the remote host and username, so it's
unlikely to overflow (or be exploitable by a remote
attacker), but there's no reason not to be careful and use
a strbuf.
Signed-off-by: Jeff King <peff@peff.net>
---
Just something I noticed while doing the cleanup in the next patch.
imap-send.c | 7 ++++---
1 files changed, 4 insertions(+), 3 deletions(-)
diff --git a/imap-send.c b/imap-send.c
index e1ad1a4..4c1e897 100644
--- a/imap-send.c
+++ b/imap-send.c
@@ -1209,9 +1209,10 @@ static int auth_cram_md5(struct imap_store *ctx, struct imap_cmd *cmd, const cha
goto bail;
}
if (!srvc->pass) {
- char prompt[80];
- sprintf(prompt, "Password (%s@%s): ", srvc->user, srvc->host);
- arg = git_getpass(prompt);
+ struct strbuf prompt = STRBUF_INIT;
+ strbuf_addf(&prompt, "Password (%s@%s): ", srvc->user, srvc->host);
+ arg = git_getpass(prompt.buf);
+ strbuf_release(&prompt);
if (!arg) {
perror("getpass");
exit(1);
--
1.7.8.rc2.8.gf0f4f
next prev parent reply other threads:[~2011-12-08 8:23 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-12-08 8:21 [PATCHv2 0/7] getpass refactoring Jeff King
2011-12-08 8:23 ` Jeff King [this message]
2011-12-08 8:24 ` [PATCH 2/7] imap-send: don't check return value of git_getpass Jeff King
2011-12-08 8:24 ` [PATCH 3/7] move git_getpass to its own source file Jeff King
2011-12-08 8:31 ` [PATCH 4/7] refactor git_getpass into generic prompt function Jeff King
2011-12-09 23:58 ` Junio C Hamano
2011-12-08 8:33 ` [PATCH 5/7] add generic terminal " Jeff King
2011-12-08 21:48 ` Jakub Narebski
2011-12-08 21:52 ` Jeff King
2011-12-08 8:33 ` [PATCH 6/7] prompt: use git_terminal_prompt Jeff King
2011-12-08 8:33 ` [PATCH 7/7] credential: use git_prompt instead of git_getpass Jeff King
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20111208082317.GA26409@sigill.intra.peff.net \
--to=peff@peff.net \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
--cc=kusmabite@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.