1
0
mirror of https://github.com/hashcat/hashcat.git synced 2024-12-23 23:19:09 +00:00

Merge pull request #1108 from philsmd/master

tainted string: test number 2, try to limit the length of the compute variable
This commit is contained in:
Jens Steube 2017-02-15 13:49:03 +01:00 committed by GitHub
commit add3ec6f54

View File

@ -258,18 +258,18 @@ void setup_environment_variables ()
{
static char display[100];
snprintf (display, sizeof (display) - 1, "DISPLAY=%s", compute);
u32 compute_len_max = sizeof (display);
// we only use this check to avoid "tainted string" warnings
u32 display_len_max = sizeof (display);
u32 compute_len = strnlen (compute, compute_len_max);
u32 display_len = strnlen (display, display_len_max);
if (display_len > 0) // should be always true
if (compute_len > 0) // should be always true
{
if (display_len < display_len_max) // some upper bound is always good
if (compute_len < compute_len_max) // some upper bound is always good
{
snprintf (display, compute_len_max, "DISPLAY=%s", compute);
putenv (display);
}
}