From 55b59b472dd394681092f2f6f0c29fa2bec645bf Mon Sep 17 00:00:00 2001 From: Joerg Wunsch Date: Sun, 22 Dec 1996 14:57:53 +0000 Subject: YAMFC (various buffer overflow fixes) --- gnu/usr.bin/man/man/man.c | 152 +++++++++++++++++++++++----------------------- 1 file changed, 75 insertions(+), 77 deletions(-) (limited to 'gnu/usr.bin') diff --git a/gnu/usr.bin/man/man/man.c b/gnu/usr.bin/man/man/man.c index 4a88c3231283..fdfab5ad973d 100644 --- a/gnu/usr.bin/man/man/man.c +++ b/gnu/usr.bin/man/man/man.c @@ -16,15 +16,16 @@ #define MAN_MAIN +#include +#include #include -#include #include #include #ifdef __FreeBSD__ #include #endif +#include #include -#include #include #include "config.h" #include "gripes.h" @@ -61,14 +62,7 @@ extern int fclose (); extern char *sprintf (); #endif -extern char *strdup (); - -extern char **glob_vector (); extern char **glob_filename (); -extern int access (); -extern int unlink (); -extern int system (); -extern int chmod (); extern int is_newer (); extern int is_directory (); extern int do_system_command (); @@ -425,6 +419,10 @@ man_getopt (argc, argv) mp = manpathlist; for (p = manp; ; p = end+1) { + if (mp == manpathlist + MAXDIRS - 1) { + fprintf (stderr, "Warning: too many directories in manpath, truncated!\n"); + break; + } if ((end = strchr (p, ':')) != NULL) *end = '\0'; @@ -437,9 +435,7 @@ man_getopt (argc, argv) fprintf (stderr, "Alternate system `%s' specified\n", alt_system_name); - strcpy (buf, p); - strcat (buf, "/"); - strcat (buf, alt_system_name); + snprintf(buf, sizeof(buf), "%s/%s", p, alt_system_name); mp = add_dir_to_mpath_list (mp, buf); } @@ -539,15 +535,17 @@ convert_name (name, to_cat) #ifdef DO_COMPRESS if (to_cat) { - int len = strlen (name) + 3; + int olen = strlen(name); int cextlen = strlen(COMPRESS_EXT); + int len = olen + cextlen; - to_name = (char *) malloc (len); + to_name = malloc (len+1); if (to_name == NULL) - gripe_alloc (len, "to_name"); + gripe_alloc (len+1, "to_name"); strcpy (to_name, name); + olen -= cextlen; /* Avoid tacking it on twice */ - if (strcmp(name + (len - (3 + cextlen)), COMPRESS_EXT)) + if (olen >= 1 && strcmp(name + olen, COMPRESS_EXT) != 0) strcat (to_name, COMPRESS_EXT); } else @@ -605,9 +603,9 @@ glob_for_file (path, section, name, cat) char **gf; if (cat) - sprintf (pathname, "%s/cat%s/%s.%s*", path, section, name, section); + snprintf (pathname, sizeof(pathname), "%s/cat%s/%s.%s*", path, section, name, section); else - sprintf (pathname, "%s/man%s/%s.%s*", path, section, name, section); + snprintf (pathname, sizeof(pathname), "%s/man%s/%s.%s*", path, section, name, section); if (debug) fprintf (stderr, "globbing %s\n", pathname); @@ -617,18 +615,18 @@ glob_for_file (path, section, name, cat) if ((gf == (char **) -1 || *gf == NULL) && isdigit (*section)) { if (cat) - sprintf (pathname, "%s/cat%s/%s.%c*", path, section, name, *section); + snprintf (pathname, sizeof(pathname), "%s/cat%s/%s.%c*", path, section, name, *section); else - sprintf (pathname, "%s/man%s/%s.%c*", path, section, name, *section); + snprintf (pathname, sizeof(pathname), "%s/man%s/%s.%c*", path, section, name, *section); gf = glob_filename (pathname); } if ((gf == (char **) -1 || *gf == NULL) && isdigit (*section)) { if (cat) - sprintf (pathname, "%s/cat%s/%s.0*", path, section, name); + snprintf (pathname, sizeof(pathname), "%s/cat%s/%s.0*", path, section, name); else - sprintf (pathname, "%s/man%s/%s.0*", path, section, name); + snprintf (pathname, sizeof(pathname), "%s/man%s/%s.0*", path, section, name); if (debug) fprintf (stderr, "globbing %s\n", pathname); gf = glob_filename (pathname); @@ -652,9 +650,9 @@ make_name (path, section, name, cat) char buf[FILENAME_MAX]; if (cat) - sprintf (buf, "%s/cat%s/%s.%s", path, section, name, section); + snprintf (buf, sizeof(buf), "%s/cat%s/%s.%s", path, section, name, section); else - sprintf (buf, "%s/man%s/%s.%s", path, section, name, section); + snprintf (buf, sizeof(buf), "%s/man%s/%s.%s", path, section, name, section); if (access (buf, R_OK) == 0) names[i++] = strdup (buf); @@ -667,9 +665,9 @@ make_name (path, section, name, cat) if (section[1] != '\0') { if (cat) - sprintf (buf, "%s/cat%c/%s.%s", path, section[0], name, section); + snprintf (buf, sizeof(buf), "%s/cat%c/%s.%s", path, section[0], name, section); else - sprintf (buf, "%s/man%c/%s.%s", path, section[0], name, section); + snprintf (buf, sizeof(buf), "%s/man%c/%s.%s", path, section[0], name, section); if (access (buf, R_OK) == 0) names[i++] = strdup (buf); @@ -722,9 +720,9 @@ display_cat_file (file) char *expander = get_expander (file); if (expander != NULL) - sprintf (command, "%s %s | %s", expander, file, pager); + snprintf (command, sizeof(command), "%s %s | %s", expander, file, pager); else - sprintf (command, "%s %s", pager, file); + snprintf (command, sizeof(command), "%s %s", pager, file); found = do_system_command (command); } @@ -751,8 +749,10 @@ ultimate_source (name, path) char *beg; char *end; - strcpy (ult, name); - strcpy (buf, name); + strncpy (ult, name, sizeof(ult)-1); + ult[sizeof(ult)-1] = '\0'; + strncpy (buf, name, sizeof(buf)-1); + ult[sizeof(buf)-1] = '\0'; next: @@ -777,11 +777,8 @@ ultimate_source (name, path) *end = '\0'; - strcpy (ult, path); - strcat (ult, "/"); - strcat (ult, beg); - - strcpy (buf, ult); + snprintf(ult, sizeof(ult), "%s/%s", path, beg); + snprintf(buf, sizeof(buf), "%s", ult); goto next; } @@ -793,34 +790,34 @@ ultimate_source (name, path) } void -add_directive (first, d, file, buf) +add_directive (first, d, file, buf, bufsize) int *first; char *d; char *file; char *buf; + int bufsize; { if (strcmp (d, "") != 0) { if (*first) { *first = 0; - strcpy (buf, d); - strcat (buf, " "); - strcat (buf, file); + snprintf(buf, bufsize, "%s %s", d, file); } else { - strcat (buf, " | "); - strcat (buf, d); + strncat (buf, " | ", bufsize-strlen(buf)-1); + strncat (buf, d, bufsize-strlen(buf)-1); } } } int -parse_roff_directive (cp, file, buf) +parse_roff_directive (cp, file, buf, bufsize) char *cp; char *file; char *buf; + int bufsize; { char c; int first = 1; @@ -836,9 +833,9 @@ parse_roff_directive (cp, file, buf) fprintf (stderr, "found eqn(1) directive\n"); if (troff) - add_directive (&first, EQN, file, buf); + add_directive (&first, EQN, file, buf, bufsize); else - add_directive (&first, NEQN, file, buf); + add_directive (&first, NEQN, file, buf, bufsize); break; @@ -847,7 +844,7 @@ parse_roff_directive (cp, file, buf) if (debug) fprintf (stderr, "found grap(1) directive\n"); - add_directive (&first, GRAP, file, buf); + add_directive (&first, GRAP, file, buf, bufsize); break; @@ -856,7 +853,7 @@ parse_roff_directive (cp, file, buf) if (debug) fprintf (stderr, "found pic(1) directive\n"); - add_directive (&first, PIC, file, buf); + add_directive (&first, PIC, file, buf, bufsize); break; @@ -866,7 +863,7 @@ parse_roff_directive (cp, file, buf) fprintf (stderr, "found tbl(1) directive\n"); tbl_found++; - add_directive (&first, TBL, file, buf); + add_directive (&first, TBL, file, buf, bufsize); break; case 'v': @@ -874,7 +871,7 @@ parse_roff_directive (cp, file, buf) if (debug) fprintf (stderr, "found vgrind(1) directive\n"); - add_directive (&first, VGRIND, file, buf); + add_directive (&first, VGRIND, file, buf, bufsize); break; case 'r': @@ -882,7 +879,7 @@ parse_roff_directive (cp, file, buf) if (debug) fprintf (stderr, "found refer(1) directive\n"); - add_directive (&first, REFER, file, buf); + add_directive (&first, REFER, file, buf, bufsize); break; case ' ': @@ -905,19 +902,19 @@ parse_roff_directive (cp, file, buf) #ifdef HAS_TROFF if (troff) { - strcat (buf, " | "); - strcat (buf, TROFF); + strncat (buf, " | ", bufsize-strlen(buf)-1); + strncat (buf, TROFF, bufsize-strlen(buf)-1); } else #endif { - strcat (buf, " | "); - strcat (buf, NROFF); + strncat (buf, " | ", bufsize-strlen(buf)-1); + strncat (buf, NROFF, bufsize-strlen(buf)-1); } if (tbl_found && !troff && strcmp (COL, "") != 0) { - strcat (buf, " | "); - strcat (buf, COL); + strncat (buf, " | ", bufsize-strlen(buf)-1); + strncat (buf, COL, bufsize-strlen(buf)-1); } return 0; @@ -938,7 +935,7 @@ make_roff_command (file) if (debug) fprintf (stderr, "parsing directive from command line\n"); - status = parse_roff_directive (roff_directive, file, buf); + status = parse_roff_directive (roff_directive, file, buf, sizeof(buf)); if (status == 0) return buf; @@ -950,13 +947,13 @@ make_roff_command (file) if ((fp = fopen (file, "r")) != NULL) { cp = line; - fgets (line, 100, fp); + fgets (line, BUFSIZ, fp); if (*cp++ == '\'' && *cp++ == '\\' && *cp++ == '"' && *cp++ == ' ') { if (debug) fprintf (stderr, "parsing directive from file\n"); - status = parse_roff_directive (cp, file, buf); + status = parse_roff_directive (cp, file, buf, sizeof(buf)); fclose (fp); @@ -982,7 +979,7 @@ make_roff_command (file) if (debug) fprintf (stderr, "parsing directive from environment\n"); - status = parse_roff_directive (cp, file, buf); + status = parse_roff_directive (cp, file, buf, sizeof(buf)); if (status == 0) return buf; @@ -996,19 +993,19 @@ make_roff_command (file) if ((cp = get_expander(file)) == NULL) cp = "/bin/cat"; - sprintf(buf, "%s %s | ", cp, file); + snprintf(buf, sizeof(buf), "%s %s | ", cp, file); #ifdef HAS_TROFF if (troff) { if (strcmp (TBL, "") != 0) { - strcat (buf, TBL); - strcat (buf, " | "); - strcat (buf, TROFF); + strncat(buf, TBL, sizeof(buf)-strlen(buf)-1); + strncat(buf, " | ", sizeof(buf)-strlen(buf)-1); + strncat(buf, TROFF, sizeof(buf)-strlen(buf)-1); } else { - strcat (buf, TROFF); + strncat(buf, TROFF, sizeof(buf)-strlen(buf)-1); } } else @@ -1016,19 +1013,19 @@ make_roff_command (file) { if (strcmp (TBL, "") != 0) { - strcat (buf, TBL); - strcat (buf, " | "); - strcat (buf, NROFF); + strncat(buf, TBL, sizeof(buf)-strlen(buf)-1); + strncat(buf, " | ", sizeof(buf)-strlen(buf)-1); + strncat(buf, NROFF, sizeof(buf)-strlen(buf)-1); } else { - strcpy (buf, NROFF); + strncpy (buf, NROFF, sizeof(buf)); } if (strcmp (COL, "") != 0) { - strcat (buf, " | "); - strcat (buf, COL); + strncat (buf, " | ", sizeof(buf)-strlen(buf)-1); + strncat (buf, COL, sizeof(buf)-strlen(buf)-1); } } return buf; @@ -1080,7 +1077,7 @@ make_cat_file (path, man_file, cat_file, manid) if (roff_command == NULL) return 0; - sprintf(temp, "%s.tmpXXXXXX", cat_file); + snprintf(temp, sizeof(temp), "%s.tmpXXXXXX", cat_file); if ((f = mkstemp(temp)) >= 0 && (fp = fdopen(f, "w")) != NULL) { set_sigs(); @@ -1095,10 +1092,10 @@ make_cat_file (path, man_file, cat_file, manid) fprintf (stderr, "mode of %s is now %o\n", temp, CATMODE); #ifdef DO_COMPRESS - sprintf (command, "(cd %s ; %s | %s)", path, + snprintf (command, sizeof(command), "(cd %s ; %s | %s)", path, roff_command, COMPRESSOR); #else - sprintf (command, "(cd %s ; %s)", path, + snprintf (command, sizeof(command), "(cd %s ; %s)", path, roff_command); #endif fprintf (stderr, "Formatting page, please wait..."); @@ -1247,7 +1244,7 @@ format_and_display (path, man_file, cat_file) if (roff_command == NULL) return 0; else - sprintf (command, "(cd %s ; %s)", path, roff_command); + snprintf (command, sizeof(command), "(cd %s ; %s)", path, roff_command); found = do_system_command (command); } @@ -1327,7 +1324,7 @@ format_and_display (path, man_file, cat_file) if (roff_command == NULL) return 0; else - sprintf (command, "(cd %s ; %s | %s)", path, + snprintf (command, sizeof(command), "(cd %s ; %s | %s)", path, roff_command, pager); found = do_system_command (command); @@ -1516,7 +1513,8 @@ get_section_list () int i; char *p; char *end; - static char *tmp_section_list[100]; +#define TMP_SECTION_LIST_SIZE 100 + static char *tmp_section_list[TMP_SECTION_LIST_SIZE]; if (colon_sep_section_list == NULL) { @@ -1531,7 +1529,7 @@ get_section_list () } i = 0; - for (p = colon_sep_section_list; ; p = end+1) + for (p = colon_sep_section_list; i < TMP_SECTION_LIST_SIZE ; p = end+1) { if ((end = strchr (p, ':')) != NULL) *end = '\0'; -- cgit v1.3