Преглед на файлове

Make sure strncpy(3)d buffers are nul-terminated.

git-svn-id: https://nagiosplug.svn.sourceforge.net/svnroot/nagiosplug/nagiosplug/trunk@1764 f882894a-f735-0410-b71e-b25c423dba1c
Holger Weiss преди 18 години
родител
ревизия
6f60c0ac81
променени са 1 файла, в които са добавени 6 реда и са изтрити 3 реда
  1. 6 3
      plugins-root/check_dhcp.c

+ 6 - 3
plugins-root/check_dhcp.c

@@ -313,7 +313,8 @@ int get_hardware_address(int sock,char *interface_name){
 #if defined(__linux__)
 #if defined(__linux__)
 	struct ifreq ifr;
 	struct ifreq ifr;
 
 
-	strncpy((char *)&ifr.ifr_name,interface_name,sizeof(ifr.ifr_name));
+	strncpy((char *)&ifr.ifr_name,interface_name,sizeof(ifr.ifr_name)-1);
+	ifr.ifr_name[sizeof(ifr.ifr_name)-1]='\0';
 	
 	
 	/* try and grab hardware address of requested interface */
 	/* try and grab hardware address of requested interface */
 	if(ioctl(sock,SIOCGIFHWADDR,&ifr)<0){
 	if(ioctl(sock,SIOCGIFHWADDR,&ifr)<0){
@@ -773,14 +774,16 @@ int create_dhcp_socket(void){
 
 
 	/* bind socket to interface */
 	/* bind socket to interface */
 #if defined(__linux__)
 #if defined(__linux__)
-	strncpy(interface.ifr_ifrn.ifrn_name,network_interface_name,IFNAMSIZ);
+	strncpy(interface.ifr_ifrn.ifrn_name,network_interface_name,IFNAMSIZ-1);
+	interface.ifr_ifrn.ifrn_name[IFNAMSIZ-1]='\0';
 	if(setsockopt(sock,SOL_SOCKET,SO_BINDTODEVICE,(char *)&interface,sizeof(interface))<0){
 	if(setsockopt(sock,SOL_SOCKET,SO_BINDTODEVICE,(char *)&interface,sizeof(interface))<0){
 		printf(_("Error: Could not bind socket to interface %s.  Check your privileges...\n"),network_interface_name);
 		printf(_("Error: Could not bind socket to interface %s.  Check your privileges...\n"),network_interface_name);
 		exit(STATE_UNKNOWN);
 		exit(STATE_UNKNOWN);
 	        }
 	        }
 
 
 #else
 #else
-	strncpy(interface.ifr_name,network_interface_name,IFNAMSIZ);
+	strncpy(interface.ifr_name,network_interface_name,IFNAMSIZ-1);
+	interface.ifr_name[IFNAMSIZ-1]='\0';
 #endif
 #endif
 
 
         /* bind the socket */
         /* bind the socket */