Send inn-workers mailing list submissions to
        [email protected]

To subscribe or unsubscribe via the World Wide Web, visit
        https://lists.isc.org/mailman/listinfo/inn-workers
or, via email, send a message with subject or body 'help' to
        [email protected]

You can reach the person managing the list at
        [email protected]

When replying, please edit your Subject line so it is more specific
than "Re: Contents of inn-workers digest..."


Today's Topics:

   1. inn-2.5.3 bug report (David Binderman)


----------------------------------------------------------------------

Message: 1
Date: Thu, 13 Jun 2013 11:00:49 +0000
From: David Binderman <[email protected]>
To: "[email protected]" <[email protected]>
Subject: inn-2.5.3 bug report
Message-ID: <[email protected]>
Content-Type: text/plain; charset="iso-8859-1"

Hello there,

I just ran the static analyser "cppcheck" over the source code of
inn-2.5.3 It said, amongst other things

[imap_connection.c:2386]: (error) Buffer is accessed out of bounds.

Offending source code is

??? sprintf(cxn->imap_currentTag,"%06d",cxn->imap_tag_num);

and

??? char imap_currentTag[IMAP_TAGLENGTH];

and

#define IMAP_TAGLENGTH 6

sprintf writes a trailing zero byte, so 6 + 1 into 6 won't go. Suggest
code rework.

Regards

David Binderman                                           

------------------------------

_______________________________________________
inn-workers mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/inn-workers

End of inn-workers Digest, Vol 52, Issue 2
******************************************

Reply via email to