LWN.net Logo

catdoc: denial of service

catdoc: denial of service

Posted Nov 15, 2012 12:58 UTC (Thu) by lacos (subscriber, #70616)
Parent article: catdoc: denial of service

I have no idea how the FormatIdxUsed array is used before and after the loop, but the bogus semicolon of course prevents zeroing the array as well! If the array is filled with user-provided data before the loop, and then used later in ways that would depend on the (missing) zeroing, there might be trouble.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds