From 6e53930073e1d7dd604bc3bf3d265c7f1a557cf9 Mon Sep 17 00:00:00 2001 From: ngie Date: Fri, 13 May 2016 08:34:53 +0000 Subject: [PATCH] MFstable/10 r299619: MFC r298336: r298336 (by cem): kgssapi(4): Fix string overrun in Kerberos principal construction 'buf.value' was previously treated as a nul-terminated string, but only allocated with strlen() space. Rectify this. CID: 1007639 git-svn-id: svn://svn.freebsd.org/base/stable/9@299620 ccf9f872-aa2e-dd11-9fc8-001c23d0bc1f --- sys/rpc/rpcsec_gss/svc_rpcsec_gss.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c b/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c index 64e691e30..784dd7f04 100644 --- a/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c +++ b/sys/rpc/rpcsec_gss/svc_rpcsec_gss.c @@ -334,7 +334,7 @@ rpc_gss_get_principal_name(rpc_gss_principal_t *principal, * Construct a gss_buffer containing the full name formatted * as "name/node@domain" where node and domain are optional. */ - namelen = strlen(name); + namelen = strlen(name) + 1; if (node) { namelen += strlen(node) + 1; } -- 2.45.0