https://bugzilla.mindrot.org/show_bug.cgi?id=3625

            Bug ID: 3625
           Summary: potentially uninitialized local pointer in
                    send_handle() in sftp-server.c
           Product: Portable OpenSSH
           Version: 9.5p1
          Hardware: All
                OS: All
            Status: NEW
          Severity: trivial
          Priority: P5
         Component: sftp-server
          Assignee: [email protected]
          Reporter: [email protected]

Overview:
string is uninitialized.

static void
send_handle(u_int32_t id, int handle)
{
        u_char *string;
        int hlen;

        handle_to_string(handle, &string, &hlen);
        debug("request %u: sent handle %d", id, handle);
        send_data_or_handle(SSH2_FXP_HANDLE, id, string, hlen);
        free(string);
}

Expected Result:
u_char *string = NULL;

Additional Information:
Corresponding compiler warning -
https://learn.microsoft.com/en-us/cpp/error-messages/compiler-warnings/compiler-warning-level-4-c4703?view=msvc-170&f1url=%3FappId%3DDev16IDEF1%26l%3DEN-US%26k%3Dk(C4703)%26rd%3Dtrue

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
_______________________________________________
openssh-bugs mailing list
[email protected]
https://lists.mindrot.org/mailman/listinfo/openssh-bugs

Reply via email to