4 ms·
As mentioned earlier, pv have been around for ages and does this "the right way" (tm). Also, as an exercise, spot the potential buffer overflow in this source i
by khanan 11y ago
As mentioned earlier, pv have been around for ages and does this "the right way" (tm). Also, as an exercise, spot the potential buffer overflow in this source in less than 10 seconds for extra credits!
- rodrickbrown 11y agostrcpy(new->format, format);
- ised 11y agoI prefer progress(1) written for BSD UNIX. Dates back to 2002.
- _RPM 11y agohttps://github.com/doches/progressbar/blob/master/lib/progressbar.c#L28:L30 https://github.com/doches/progressbar/blob/master/lib/progre... The correct solution would be a) check the length of format, and if it less than or equal to 4 but greater than 0, then copy the bytes, else, don't... I guess? Why is 4 such an arbitrary chosen number? // new->format is allocated to 4 bytes size_t len = strlen(format); if(len > 0 && len <= 4) { memcpy(new->format, format, len); //i to < 4 new->format[3] = '\0'; } Or it just be better to allocate the new->length to the return value of strlen(format) + 1.
- danieldk 11y agoMaybe I am not awake yet (just rolled out of bed), but if new->format is allocated to 4 bytes, then new->format[4] = '\0'; is out of bounds, no?
- _RPM 11y agoYes it was. Good catch. The size of the buffer is 4, so the last byte would be located at 4-1 = index 3. Because we're 0 based...Wow can't believe I did that. it's 12:30 AM here and I've had a few beers tonight. It's common to allocate your size needed plus 1 for the NULL byte. But this programmer only allocates 4 bytes.. with no thought of the NULL byte at the end.