[Midnight Commander] #241: buffer overflow in __mhl_str_concat_hlp

Ticket System tickets at midnight-commander.org
Tue Feb 3 18:43:03 UTC 2009


#241: buffer overflow in __mhl_str_concat_hlp
--------------------------------------------------+-------------------------
 Reporter:  Patrick Winnertz <winnie at debian.org>  |       Owner:       
     Type:  defect                                |      Status:  new  
 Priority:  major                                 |   Milestone:  4.7  
Component:  mc-core                               |     Version:  4.6.2
 Keywords:                                        |    Blocking:       
Blockedby:                                        |  
--------------------------------------------------+-------------------------
 Hey,

 There is currently a bufferoverflow in __mhl_str_concat_hlp if the
 function is
 called with more than 32 parameters.

 This will fix this:
 {{{
 while ((a = va_arg(args, char*)) != (char*)1 && count <=31) { ... }
 }}}

-- 
Ticket URL: <www.midnight-commander.org/ticket/241>
Midnight Commander <www.midnight-commander.org>
Midnight Development Center


More information about the mc-devel mailing list