4 ms·
My C is a little rusty, but it seems like this web server is definitely not safe. The very first function in the code has a local stack variable and uses sprin
by pblakeney 13y ago
My C is a little rusty, but it seems like this web server is definitely not safe. The very first function in the code has a local stack variable and uses sprintf() to fill it. That's almost a textbook example of a buffer overflow vulnerability, if I'm not mistaken. Even if they try and compensate for that by checking the data length before it's passed to that function, it's still scary to see someone using sprintf() instead of snprintf() these days. It's like walking a tightrope without a net.
- nknighthb 13y agoIt's scary style (and speaking of style, this code is really inconsistent in its formatting), but from a quick search of the usages of the logger function, I didn't see any way to overflow the buffer. * BUFSIZE is 8096. * logbuffer (the local variable) is BUFSIZEx2 * s1 looks like it's always trusted and an order of magnitude smaller than BUFSIZE. * The format strings and numbers are nowhere near big enough to make up the difference. * Where s2 is untrusted data, I think it's always guaranteed to be <=BUFSIZE and zero-terminated. But there are definitely other possible issues I haven't looked at closely, and I'm certainly troubled that this mess has showed up on an IBM site as an example of a "safe" web server.