Fix CVE-2008-2149: buffer overflows by limiting the length of the string in sprintf format string Closes: #481186 (CVE-2008-2149) Please note: The WordNet code contains several other occurences of potentially exploitable functions like strcpy()/strcat()/... and so even if there are no known exploits the code needs a full security audit. --- a/src/wn.c +++ b/src/wn.c @@ -206,7 +206,8 @@ static int searchwn(int ac, char *av[]) outsenses += do_search(av[1], optptr->pos, optptr->search, whichsense, optptr->label); } else { - sprintf(tmpbuf, "wn: invalid search option: %s\n", av[j]); + /* Fix CVE-2008-2149: buffer overflows Andreas Tille */ + sprintf(tmpbuf, "wn: invalid search option: %.200s\n", av[j]); display_message(tmpbuf); errcount++; } scripts Wojtek's customized Guix
aboutsummaryrefslogtreecommitdiff
path: root/gnu/home.scm
AgeCommit message (Expand)Author
2023-03-20home: 'home-environment-with-provenance' uses the HE location info....Sergey Trofimov
2023-03-13home: Export home-environment-packages....Sergey Trofimov
2022-08-19home: Fix docstring....Andrew Tropin
2022-08-01home: Add 'home-generation-base'....Ludovic Courtès
2022-07-17Revert "home: Add 'home-generation-base'."...Tobias Geerinckx-Rice
2022-07-23home: Add 'home-generation-base'....Ludovic Courtès
2021-12-19home: Add gexp-compiler for home-environments....Andrew Tropin
2021-10-09Move (gnu home-services) to (gnu home services)....Oleg Pykhalov
2021-10-08gnu: Move (gnu home-services) to (gnu home services)....Oleg Pykhalov
2021-09-09gnu: home: Add doc comment about the module....Andrew Tropin
2021-09-09home: Add home-environment....Andrew Tropin