Re: Buffer overflow in extract_diag_error_w()

Nick Gorham <[email protected]> Wed, 11 Nov 2015 10:55:41 +0000
Newsgroups gmane.comp.db.unixodbc.devel
Message-ID <[email protected]>
On 11/11/15 10:36, Nick Gorham wrote:
> On 11/11/15 10:22, Andrew Punch wrote:
>> Hi,
>>
>> I rewrote the patch so that the message is truncated.
>>
>> diff -ur unixODBC-2.3.1/DriverManager/__info.c 
>> unixodbc-2.3.1-patched/DriverManager/__info.c
>> --- unixODBC-2.3.1/DriverManager/__info.c   2011-11-15 
>> 22:43:15.000000000 +1100
>> +++ unixodbc-2.3.1-patched/DriverManager/__info.c   2015-11-11 
>> 20:16:24.585057248 +1100
>> @@ -4460,7 +4460,7 @@
>>              SQLWCHAR *tmp;
>>
>>  #ifdef STRICT_ODBC_ERROR
>> -            wide_strcpy( msg, msg1 );
>> +            wide_strncpy( msg, msg1, SQL_MAX_MESSAGE_LENGTH);
>>  #else
>>              tmp = ansi_to_unicode_alloc((SQLCHAR*) ERROR_PREFIX, 
>> SQL_NTS, connection );
>>              wide_strcpy( msg, tmp );
>> @@ -4640,7 +4640,7 @@
>>                  as1 = (SQLCHAR*) unicode_to_ansi_alloc( sqlstate, 
>> SQL_NTS, connection );
>>                  as2 = (SQLCHAR*) unicode_to_ansi_alloc( msg1, 
>> SQL_NTS, connection );
>>
>> -                sprintf( connection -> msg, "\t\tDIAG [%s] %s",
>> +                snprintf( connection -> msg, SQL_MAX_MESSAGE_LENGTH, 
>> "\t\tDIAG [%s] %s",
>>                          as1, as2 );
>>
>>                  if( as1 ) free( as1 );
>> _______________________________________________
>> unixODBC-dev mailing list
>> [email protected]
>> http://mailman.unixodbc.org/mailman/listinfo/unixodbc-dev
>
> Ok, but how does a message string thats longer than 
> SQL_MAX_MESSAGE_LENGTH come out of
>
>         ret = SQLError(
>                 henv,
>                 hdbc,
>                 hstmt,
>                 sqlstate,
>                 &native,
>                 msg1,
>                 sizeof( msg1 ),
>                 &len );
>
> Given that sizeof( msg1 ) == SQL_MAX_MESSAGE_LENGTH
>
> Or an I still looking at different code to you in 2.3.1 and 2.3.5-pre?
>

I have committed a change to 2.3.5-pre that should make sure that the 
buffer is not overrun. But if the driver SQLError writes more that the 
buffer length of characters to the supplied buffer thats out of my control.

-- 
Nick
_______________________________________________
unixODBC-dev mailing list
[email protected]
http://mailman.unixodbc.org/mailman/listinfo/unixodbc-dev