qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [5966] Fix off-by-one bug limiting VNC passwords to 7 chars (Chris Webb)
@ 2008-12-10 15:12 Anthony Liguori
  0 siblings, 0 replies; only message in thread
From: Anthony Liguori @ 2008-12-10 15:12 UTC (permalink / raw)
  To: qemu-devel

Revision: 5966
          http://svn.sv.gnu.org/viewvc/?view=rev&root=qemu&revision=5966
Author:   aliguori
Date:     2008-12-10 15:12:57 +0000 (Wed, 10 Dec 2008)

Log Message:
-----------
Fix off-by-one bug limiting VNC passwords to 7 chars (Chris Webb)

monitor_readline expects buf_size to include the terminating \0, but
do_change_vnc in monitor.c calls it as though it doesn't. The other site
where monitor_readline reads a password (in vl.c) passes the buffer 
length
correctly.

Signed-off-by: Chris Webb <chris@arachsys.com>
Signed-off-by: Anthony Liguori <aliguori@us.ibm.com>

Modified Paths:
--------------
    trunk/monitor.c

Modified: trunk/monitor.c
===================================================================
--- trunk/monitor.c	2008-12-10 15:02:33 UTC (rev 5965)
+++ trunk/monitor.c	2008-12-10 15:12:57 UTC (rev 5966)
@@ -434,8 +434,7 @@
     if (strcmp(target, "passwd") == 0 ||
 	strcmp(target, "password") == 0) {
 	char password[9];
-	monitor_readline("Password: ", 1, password, sizeof(password)-1);
-	password[sizeof(password)-1] = '\0';
+	monitor_readline("Password: ", 1, password, sizeof(password));
 	if (vnc_display_password(NULL, password) < 0)
 	    term_printf("could not set VNC server password\n");
     } else {

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2008-12-10 15:13 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-12-10 15:12 [Qemu-devel] [5966] Fix off-by-one bug limiting VNC passwords to 7 chars (Chris Webb) Anthony Liguori

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).