public inbox for gcc-prs@sourceware.org help / color / mirror / Atom feed
From: fw@deneb.enyo.de To: gcc-gnats@gcc.gnu.org Subject: ada/5903: Buffer overflow in temporary file creation Date: Sun, 10 Mar 2002 01:46:00 -0000 [thread overview] Message-ID: <20020310093649.27152.qmail@sources.redhat.com> (raw) >Number: 5903 >Category: ada >Synopsis: Buffer overflow in temporary file creation >Confidential: no >Severity: serious >Priority: medium >Responsible: unassigned >State: open >Class: sw-bug >Submitter-Id: net >Arrival-Date: Sun Mar 10 01:46:00 PST 2002 >Closed-Date: >Last-Modified: >Originator: fw@deneb.enyo.de >Release: 3.1 20020308 (prerelease), 3.2 20020308 (experimental) >Organization: >Environment: i686-pc-linux-gnu >Description: There is a buffer overflow bug in adaint.c:__gnat_tmp_name() (inside the #ifdef linux). This bug could lead to unsafe setuid/setgid programs on GNU/Linux systems. >How-To-Repeat: >Fix: Limit the length of the string copied from the TMPDIR environment variable. >Release-Note: >Audit-Trail: >Unformatted:
next reply other threads:[~2002-03-10 9:46 UTC|newest] Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top 2002-03-10 1:46 fw [this message] 2003-05-10 21:36 Dara Hazeghi 2003-05-12 0:26 Dara Hazeghi
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20020310093649.27152.qmail@sources.redhat.com \ --to=fw@deneb.enyo.de \ --cc=gcc-gnats@gcc.gnu.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).