summaryrefslogtreecommitdiffstats
path: root/pw/tests
diff options
context:
space:
mode:
authorDon Lewis <truckman@FreeBSD.org>2016-05-24 05:02:24 +0000
committerDon Lewis <truckman@FreeBSD.org>2016-05-24 05:02:24 +0000
commit72c791863f4747db7f1a675767920499d9f4fdcd (patch)
treeb7c31b7bb21746c2756a58922bc37debcde0579b /pw/tests
parent89de07c3d8673ba8e991ba433f1f57c008521a84 (diff)
downloadpw-darwin-72c791863f4747db7f1a675767920499d9f4fdcd.tar.gz
pw-darwin-72c791863f4747db7f1a675767920499d9f4fdcd.tar.zst
pw-darwin-72c791863f4747db7f1a675767920499d9f4fdcd.zip
Fix CID 1006692 in /usr/sbin/pw pw_log() function and other fixes
The length of the name returned from the $LOGNAME and $USER can be very long and it was being concatenated to a fixed length buffer with no bounds checking. Fix this problem by limiting the length of the name copied. Additionally, this name is actually used to create a format string to be used in adding log file entries so embedded % characters in the name could confuse *printf(), and embedded whitespace could confuse a log file parser. Handle the former by escaping each % with an additional %, and handle the latter by simply stripping it out. Clean up the code by moving the variable declarations to the top of the function, formatting them to conform with style, and moving intialization elsewhere. Reduce code indentation by returning early in a couple of places. Reported by: Coverity CID: 1006692 Reviewed by: markj (previous version) MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D6490
Diffstat (limited to 'pw/tests')
0 files changed, 0 insertions, 0 deletions