public inbox for glibc-bugs@sourceware.org
help / color / mirror / Atom feed
From: "fweimer at redhat dot com" <sourceware-bugzilla@sourceware.org>
To: glibc-bugs@sourceware.org
Subject: [Bug stdio/12701] scanf accepts non-matching input
Date: Fri, 13 Jun 2014 14:54:00 -0000 [thread overview]
Message-ID: <bug-12701-131-30Iysn3K8G@http.sourceware.org/bugzilla/> (raw)
In-Reply-To: <bug-12701-131@http.sourceware.org/bugzilla/>
https://sourceware.org/bugzilla/show_bug.cgi?id=12701
Florian Weimer <fweimer at redhat dot com> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |fweimer at redhat dot com
Flags| |security+
--- Comment #16 from Florian Weimer <fweimer at redhat dot com> ---
(In reply to Rich Felker from comment #0)
> sscanf("abc", "%4c", buf) returns 1 instead of 0 or EOF (not sure which is
> correct) and leaves no way for the caller to know buf[3] is unfilled.
So this is an information leak.
--
You are receiving this mail because:
You are on the CC list for the bug.
next prev parent reply other threads:[~2014-06-13 14:54 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-04-25 15:13 [Bug libc/12701] New: " bugdal at aerifal dot cx
2011-05-02 1:40 ` [Bug libc/12701] " drepper.fsp at gmail dot com
2011-05-02 2:36 ` bugdal at aerifal dot cx
2011-05-03 0:31 ` drepper.fsp at gmail dot com
2011-05-03 0:40 ` bugdal at aerifal dot cx
2011-05-03 1:14 ` drepper.fsp at gmail dot com
2011-05-03 2:24 ` bugdal at aerifal dot cx
2011-09-25 4:42 ` bugdal at aerifal dot cx
2011-10-29 17:14 ` drepper.fsp at gmail dot com
2011-10-29 21:24 ` bugdal at aerifal dot cx
2011-10-29 21:37 ` drepper.fsp at gmail dot com
2011-10-29 22:04 ` ldv at altlinux dot org
2011-10-30 5:43 ` bugdal at aerifal dot cx
2012-02-21 2:12 ` [Bug stdio/12701] " jsm28 at gcc dot gnu.org
2012-03-17 20:39 ` bugdal at aerifal dot cx
2012-03-18 17:17 ` jsm28 at gcc dot gnu.org
2012-04-18 5:23 ` bugdal at aerifal dot cx
2012-11-26 8:26 ` allachan at au1 dot ibm.com
2014-06-13 14:54 ` fweimer at redhat dot com [this message]
2014-06-27 14:00 ` fweimer at redhat dot com
2021-02-10 19:30 ` bnnf-yellowbot at blurcompany dot com
2021-03-05 15:27 ` bnnf at yahoo dot com
2021-09-15 2:40 ` namboru at jasaseo dot one
2023-07-18 11:44 ` vincent-srcware at vinc17 dot net
2023-07-18 12:01 ` vincent-srcware at vinc17 dot net
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bug-12701-131-30Iysn3K8G@http.sourceware.org/bugzilla/ \
--to=sourceware-bugzilla@sourceware.org \
--cc=glibc-bugs@sourceware.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).