[tor-bugs] #4529 [Tor Client]: tor_dup_addr(): buf[] uninited for some cases
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Mon Nov 21 13:22:22 UTC 2011
#4529: tor_dup_addr(): buf[] uninited for some cases
------------------------+---------------------------------------------------
Reporter: troll_un | Owner:
Type: defect | Status: new
Priority: normal | Milestone:
Component: Tor Client | Version:
Keywords: | Parent:
Points: | Actualpoints:
------------------------+---------------------------------------------------
If tor_dup_addr() called with addr's family another than AF_INET or
AF_INET6 then call to tor_addr_to_str() leaves buf[] uninited. Calling
tor_strdup(buf) with uninited array leads to duping trash with random
length or segfault (if no zero bytes)
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/4529>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list