Vulnerability Development mailing list archives

Patch for gawk overflow


From: Dustin Childers <dustin () acm org>
Date: 20 Mar 2002 02:48:53 -0000



I tested the overflow on a FreeBSD 4.5-STABLE 
system and it worked. This patch is a patch for the 
io.c file. The error was in a strcpy(). The 'file' char 
should of been filtered before passing it on to strcpy. 
The patch has been tested and works on my system.
Thanks.

http://www.digitux.net/io.c.patch

Dustin E. Childers
Security Administrator
http://www.digitux.net
PGP Key: http://www.digitux.net/pubkey.txt


Current thread: