udhcpc6 expects string for bootfile-param opt(60)

Geoff Hanson ghanson at arista.com
Wed Feb 23 16:14:24 UTC 2022


Just following up on this patch. Are there any more comments on this?

Thanks,
Geoff

On Tue, Feb 8, 2022 at 11:58 AM Geoff Hanson <ghanson at arista.com> wrote:

> Any further feedback on this?
>
> Anything more I need to do or is what I've provided sufficient for the bug
> report?
>
> Thanks,
> Geoff
>
> On Tue, Feb 1, 2022 at 12:53 PM Geoff Hanson <ghanson at arista.com> wrote:
>
>> Hi Bernd. Can you look at my second attachment? As part of addressing the
>> issue Xabier reported,
>> I switched to using memcpy.
>>
>> Thanks,
>> Geoff
>>
>> On Tue, Feb 1, 2022 at 12:36 PM Bernd Petrovitsch <
>> bernd at petrovitsch.priv.at> wrote:
>>
>>> -Hi all!
>>>
>>> On 01.02.2022 18:12, Geoff Hanson wrote:
>>> [...]> In most cases, there's no printf directive so this just means it's
>>> > copying the string.
>>>
>>> Using some user-provided string as a format-string opens the possibility
>>> ofexploits - since decades ....
>>> > But this would cause problems in the case where the string did contain
>>> %'s.
>>>
>>> So why just not only use strncpy(), strlcpy(), memcpy() or similar?
>>>
>>> Kind regards,
>>>         Bernd
>>>
>>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.busybox.net/pipermail/busybox/attachments/20220223/4782e593/attachment-0001.html>


More information about the busybox mailing list