Merge r191298 into HEAD.

Prevent a buffer overflow in ntpq.  Patch taken from the PR database
after being committed to the official ntp tree and present in 4.2.4p7-rc2.

It will be MFH to the upcoming 7.2 pending re approval.

Obtained from:  https://support.ntp.org/bugs/show_bug.cgi?id=1144
MFC after:      3 days
Security:       http://www.securityfocus.com/bid/34481
                CVE-2009-0159
This commit is contained in:
Ollivier Robert 2009-04-20 09:59:08 +00:00
commit 0963cc7dac
Notes: svn2git 2020-12-20 02:59:44 +00:00
svn path=/head/; revision=191302

View File

@ -3185,9 +3185,9 @@ cookedprint(
if (!decodeuint(value, &uval))
output_raw = '?';
else {
char b[10];
char b[12];
(void) sprintf(b, "%03lo", uval);
(void) snprintf(b, sizeof(b), "%03lo", uval);
output(fp, name, b);
}
break;