udhcpc6 expects string for bootfile-param opt(60)

Geoff Hanson ghanson at arista.com
Tue Feb 8 19:58:24 UTC 2022


Any further feedback on this?

Anything more I need to do or is what I've provided sufficient for the bug
report?

Thanks,
Geoff

On Tue, Feb 1, 2022 at 12:53 PM Geoff Hanson <ghanson at arista.com> wrote:

> Hi Bernd. Can you look at my second attachment? As part of addressing the
> issue Xabier reported,
> I switched to using memcpy.
>
> Thanks,
> Geoff
>
> On Tue, Feb 1, 2022 at 12:36 PM Bernd Petrovitsch <
> bernd at petrovitsch.priv.at> wrote:
>
>> -Hi all!
>>
>> On 01.02.2022 18:12, Geoff Hanson wrote:
>> [...]> In most cases, there's no printf directive so this just means it's
>> > copying the string.
>>
>> Using some user-provided string as a format-string opens the possibility
>> ofexploits - since decades ....
>> > But this would cause problems in the case where the string did contain
>> %'s.
>>
>> So why just not only use strncpy(), strlcpy(), memcpy() or similar?
>>
>> Kind regards,
>>         Bernd
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.busybox.net/pipermail/busybox/attachments/20220208/f7089267/attachment.html>


More information about the busybox mailing list