cmd: fix buffer overflow in WCMD_run_program

Austin English austinenglish at gmail.com
Thu Mar 4 11:23:37 CST 2010


On Thu, Mar 4, 2010 at 11:20 AM, Eric Ho <ericho921 at gmail.com> wrote:
> Hi Guys,
>  I'm a UCLA student working with Dan Kegel on cmd.
>  This attached patch adds tests for the following buffer overflows, and
> passes on winetestbot.  Fixes http://bugs.winehq.org/show_bug.cgi?id=21344.
> Overflows fixed:
> 1. overflow due to long path name (unchecked memcpy,strcpy to thisDir)
> 2. overflow due to long file name (unchecked strcpy into stemofsearch)
> 3. overflow due to concatenating thisDir into stemofsearch (strcat)
> 4. added early breaks when getFullPathName returns an error
> 5. fixed incorrect errorlevel code (needs to be 9023 and it was 9009)

Howdy Eric,

Patches should be sent to wine-patches at winehq.org. wine-devel is for
questions/discussion, or for feedback on patches.

-- 
-Austin



More information about the wine-devel mailing list