Re: Buffer overflow in extract_diag_error_w()
Nick Gorham <[email protected]> Wed, 11 Nov 2015 10:55:41 +0000
| Newsgroups | gmane.comp.db.unixodbc.devel |
|---|---|
| Message-ID | <[email protected]> |
On 11/11/15 10:36, Nick Gorham wrote: > On 11/11/15 10:22, Andrew Punch wrote: >> Hi, >> >> I rewrote the patch so that the message is truncated. >> >> diff -ur unixODBC-2.3.1/DriverManager/__info.c >> unixodbc-2.3.1-patched/DriverManager/__info.c >> --- unixODBC-2.3.1/DriverManager/__info.c 2011-11-15 >> 22:43:15.000000000 +1100 >> +++ unixodbc-2.3.1-patched/DriverManager/__info.c 2015-11-11 >> 20:16:24.585057248 +1100 >> @@ -4460,7 +4460,7 @@ >> SQLWCHAR *tmp; >> >> #ifdef STRICT_ODBC_ERROR >> - wide_strcpy( msg, msg1 ); >> + wide_strncpy( msg, msg1, SQL_MAX_MESSAGE_LENGTH); >> #else >> tmp = ansi_to_unicode_alloc((SQLCHAR*) ERROR_PREFIX, >> SQL_NTS, connection ); >> wide_strcpy( msg, tmp ); >> @@ -4640,7 +4640,7 @@ >> as1 = (SQLCHAR*) unicode_to_ansi_alloc( sqlstate, >> SQL_NTS, connection ); >> as2 = (SQLCHAR*) unicode_to_ansi_alloc( msg1, >> SQL_NTS, connection ); >> >> - sprintf( connection -> msg, "\t\tDIAG [%s] %s", >> + snprintf( connection -> msg, SQL_MAX_MESSAGE_LENGTH, >> "\t\tDIAG [%s] %s", >> as1, as2 ); >> >> if( as1 ) free( as1 ); >> _______________________________________________ >> unixODBC-dev mailing list >> [email protected] >> http://mailman.unixodbc.org/mailman/listinfo/unixodbc-dev > > Ok, but how does a message string thats longer than > SQL_MAX_MESSAGE_LENGTH come out of > > ret = SQLError( > henv, > hdbc, > hstmt, > sqlstate, > &native, > msg1, > sizeof( msg1 ), > &len ); > > Given that sizeof( msg1 ) == SQL_MAX_MESSAGE_LENGTH > > Or an I still looking at different code to you in 2.3.1 and 2.3.5-pre? > I have committed a change to 2.3.5-pre that should make sure that the buffer is not overrun. But if the driver SQLError writes more that the buffer length of characters to the supplied buffer thats out of my control. -- Nick _______________________________________________ unixODBC-dev mailing list [email protected] http://mailman.unixodbc.org/mailman/listinfo/unixodbc-dev