From 2ef72bc15297f15397596873c4e2babaf6a02e55 Mon Sep 17 00:00:00 2001 From: Josef Karthauser Date: Sun, 30 Apr 2000 20:46:14 +0000 Subject: Fixes a potential buffer overflow with 'ed [MAXPATHLEN + 1 characters]'. Submitted by: Mike Heffner Submitted on: audit@freebsd.org --- bin/ed/main.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/bin/ed/main.c b/bin/ed/main.c index 7bff1297900a..b73738dc30cd 100644 --- a/bin/ed/main.c +++ b/bin/ed/main.c @@ -175,7 +175,9 @@ top: if (read_file(*argv, 0) < 0 && !isatty(0)) quit(2); else if (**argv != '!') - strcpy(old_filename, *argv); + if (strlcpy(old_filename, *argv, sizeof(old_filename)) + >= sizeof(old_filename)) + quit(2); } else if (argc) { fputs("?\n", stderr); if (**argv == '\0') @@ -1345,8 +1347,8 @@ strip_escapes(s) int i = 0; REALLOC(file, filesz, MAXPATHLEN + 1, NULL); - /* assert: no trailing escape */ - while ((file[i++] = (*s == '\\') ? *++s : *s)) + while (i < filesz - 1 /* Worry about a possible trailing escape */ + && (file[i++] = (*s == '\\') ? *++s : *s)) s++; return file; } -- cgit v1.3