linux-hotplug.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Sergey Vlasov <vsu@altlinux.ru>
To: linux-hotplug@vger.kernel.org
Subject: [PATCH 0/3] Fix bugs in udev_rules_apply_format()
Date: Thu, 01 Feb 2007 15:06:18 +0000	[thread overview]
Message-ID: <1170342381867-git-send-email-vsu@altlinux.ru> (raw)


Hello!

Here are fixes for several bugs in udev_rules_apply_format():

 1) fix handling of unknown format elements
 2) don't overflow the buffer when truncating substituted string
 3) do not process substituted value as format string

Without these fixes (especially the last one) udev behaves strangely
when substituting some values (due to reinterpretation of the
substituted string as a format string, which may then abuse the first
two bugs).  The problem may be triggered, e.g., by attaching an USB
storage device with a label containing '$' or '%' characters.

Combined diffstat of all patches:

 udev_rules.c |    7 ++++++-
 1 files changed, 6 insertions(+), 1 deletions(-)

If you prefer, you may pull these changes from the following git repo
and branch (based on release 104):

  git://git.altlinux.org/people/vsu/packages/udev.git alt-format-fixes

(also available over http: and rsync:, but not really useful due to
packing).

-- 
Sergey Vlasov

-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier.
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid\x120709&bid&3057&dat\x121642
_______________________________________________
Linux-hotplug-devel mailing list  http://linux-hotplug.sourceforge.net
Linux-hotplug-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-hotplug-devel

                 reply	other threads:[~2007-02-01 15:06 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1170342381867-git-send-email-vsu@altlinux.ru \
    --to=vsu@altlinux.ru \
    --cc=linux-hotplug@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).