aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorEric Andersen <andersen@codepoet.org>2002-06-06 14:36:07 +0000
committerEric Andersen <andersen@codepoet.org>2002-06-06 14:36:07 +0000
commitfe1ef2bc62883539f37e0070f62c765602232a77 (patch)
treedb2099309260e77f0f5aaae697b8fc1c54691c8d
parent6fb4e4877a9d447c45b4f511e9851f2f8f7443b3 (diff)
downloadbusybox-w32-fe1ef2bc62883539f37e0070f62c765602232a77.tar.gz
busybox-w32-fe1ef2bc62883539f37e0070f62c765602232a77.tar.bz2
busybox-w32-fe1ef2bc62883539f37e0070f62c765602232a77.zip
Fix buffer overflows noted by Gerardo Puga
-Erik
-rw-r--r--miscutils/makedevs.c6
1 files changed, 5 insertions, 1 deletions
diff --git a/miscutils/makedevs.c b/miscutils/makedevs.c
index 4e50a6d71..f55995685 100644
--- a/miscutils/makedevs.c
+++ b/miscutils/makedevs.c
@@ -52,9 +52,13 @@ int makedevs_main(int argc, char **argv)
52 52
53 if (type[0] != 'f') 53 if (type[0] != 'f')
54 dev = (major << 8) | Sminor; 54 dev = (major << 8) | Sminor;
55 strcpy(devname, basedev); 55 safe_strncpy(devname, basedev, sizeof(devname));
56 56
57 if (sbase == 0) { 57 if (sbase == 0) {
58 int len;
59 len = strlen(devname);
60 if (S > 10000 || len > (sizeof(devname)-6))
61 error_msg_and_die("%s: number too large", buf);
58 sprintf(buf, "%d", S); 62 sprintf(buf, "%d", S);
59 strcat(devname, buf); 63 strcat(devname, buf);
60 } else { 64 } else {