From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Charles Coffing" Subject: [PATCH] sxpr dereferences freed memory Date: Mon, 22 Nov 2004 13:26:37 -0700 Message-ID: Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="=__PartAD8D436D.0__=" Return-path: Sender: xen-devel-admin@lists.sourceforge.net Errors-To: xen-devel-admin@lists.sourceforge.net List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , List-Archive: To: xen-devel@lists.sourceforge.net List-Id: xen-devel@lists.xenproject.org This is a MIME message. If you are reading this text, you may want to consider changing to a mail reader or gateway that understands how to properly handle MIME multipart messages. --=__PartAD8D436D.0__= Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Content-Disposition: inline The attached patch applies to 2.0-testing. If the xfrd daemon receives a message that is immediately followed by an EOF, without first seeing whitespace (usually a newline), the sxpr parser will dereference freed memory. The attached patch fixes the dangling pointer. Thanks, Charles --=__PartAD8D436D.0__= Content-Type: application/octet-stream; name="sxpr_dangling.patch" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="sxpr_dangling.patch" PT09PT0gdG9vbHMveGZyZC9zeHByX3BhcnNlci5jIDEuMSB2cyBlZGl0ZWQgPT09PT0KLS0tIDEu MS90b29scy94ZnJkL3N4cHJfcGFyc2VyLmMJMjAwNC0wNy0wNyAwOTo1NDo0NiAtMDY6MDAKKysr IGVkaXRlZC90b29scy94ZnJkL3N4cHJfcGFyc2VyLmMJMjAwNC0xMS0yMiAxMjo1NTozOSAtMDc6 MDAKQEAgLTI0Miw2ICsyNDIsOCBAQAogICAgIGludCBlcnIgPSAwOwogICAgIFBhcnNlclN0YXRl ICpzID0gcC0+c3RhdGU7CiAgICAgcC0+c3RhdGUgPSBzLT5wYXJlbnQ7CisgICAgaWYgKHAtPnN0 YXJ0X3N0YXRlID09IHMpCisgICAgICAgIHAtPnN0YXJ0X3N0YXRlID0gTlVMTDsKICAgICBQYXJz ZXJTdGF0ZV9mcmVlKHMpOwogICAgIHJldHVybiBlcnI7CiB9CkBAIC0zNzQsNyArMzc2LDcgQEAK ICAgICBpZihDT05TUChwLT52YWwpKXsKICAgICAgICAgdiA9IHAtPnZhbDsKICAgICAgICAgcC0+ dmFsID0gT05PTkU7Ci0gICAgfSBlbHNlIGlmKENPTlNQKHAtPnN0YXJ0X3N0YXRlLT52YWwpKXsK KyAgICB9IGVsc2UgaWYocC0+c3RhcnRfc3RhdGUgJiYgQ09OU1AocC0+c3RhcnRfc3RhdGUtPnZh bCkpewogICAgICAgICB2ID0gcC0+c3RhcnRfc3RhdGUtPnZhbDsKICAgICAgICAgcC0+c3RhcnRf c3RhdGUtPnZhbCA9IE9OVUxMOwogICAgICAgICB2ID0gbnJldih2KTsK --=__PartAD8D436D.0__=-- ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/