public inbox for glibc-bugs@sourceware.org
help / color / mirror / Atom feed
* [Bug libc/14699] New: readdir_r: does not enforce NAME_MAX limit
@ 2012-10-11  9:49 fweimer at redhat dot com
  2012-10-11 14:42 ` [Bug libc/14699] " fweimer at redhat dot com
                   ` (17 more replies)
  0 siblings, 18 replies; 19+ messages in thread
From: fweimer at redhat dot com @ 2012-10-11  9:49 UTC (permalink / raw)
  To: glibc-bugs


http://sourceware.org/bugzilla/show_bug.cgi?id=14699

             Bug #: 14699
           Summary: readdir_r: does not enforce NAME_MAX limit
           Product: glibc
           Version: unspecified
            Status: NEW
          Severity: normal
          Priority: P2
         Component: libc
        AssignedTo: unassigned@sourceware.org
        ReportedBy: fweimer@redhat.com
                CC: drepper.fsp@gmail.com
    Classification: Unclassified


The sysdeps/posix/readdir_r.c implementation of readdir_r does not enforce the
NAME_MAX limit if defined by the platform.  We should add a length check,
similar to those we have for realpath and getwd.

-- 
Configure bugmail: http://sourceware.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.


^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2015-02-24 10:56 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2012-10-11  9:49 [Bug libc/14699] New: readdir_r: does not enforce NAME_MAX limit fweimer at redhat dot com
2012-10-11 14:42 ` [Bug libc/14699] " fweimer at redhat dot com
2012-10-12 11:48 ` fweimer at redhat dot com
2012-11-29 15:06 ` fweimer at redhat dot com
2012-11-29 16:03 ` fweimer at redhat dot com
2013-05-09 14:58 ` aj at suse dot de
2013-05-14 11:34 ` fweimer at redhat dot com
2013-08-16 13:38 ` fweimer at redhat dot com
2013-10-25 14:00 ` cvs-commit at gcc dot gnu.org
2013-11-01 19:01 ` cvs-commit at gcc dot gnu.org
2013-11-21 17:16 ` cvs-commit at gcc dot gnu.org
2014-01-06 16:55 ` cvs-commit at gcc dot gnu.org
2014-01-06 16:56 ` cvs-commit at gcc dot gnu.org
2014-06-12 18:53 ` [Bug libc/14699] readdir_r: does not enforce NAME_MAX limit (CVE-2013-4237) fweimer at redhat dot com
2014-06-30 18:44 ` fweimer at redhat dot com
2015-01-16 16:59 ` cvs-commit at gcc dot gnu.org
2015-01-29 18:49 ` cvs-commit at gcc dot gnu.org
2015-02-23 15:03 ` cvs-commit at gcc dot gnu.org
2015-02-24 10:56 ` fweimer at redhat dot com

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).