[collectd] collectd 4.0.2 buffer clearing is csv.c and rrdtool.c does not happen...

Florian Forster octo at verplant.org
Tue Jun 19 08:19:43 CEST 2007


Hi Ezra,

On Mon, Jun 18, 2007 at 05:24:31PM -0400, ezra peisach wrote:
> In csv.c (line 44) and rrdtool.c (line 363) (value_list_to_string)
> the following syntax exists:
> 
>   memset (buffer, '\0', sizeof (buffer_len));

oh, that's of course not intended. I've fixed that in the repository.

> Based on the code paths - I do not see an information leak - or any
> security implications...

I don't think there's a security problem either..

I've applied your patch to src/Makefile.am, too. Both changes will be
included in the next patch release which is due soon (today, I think).

Thank you very much for your bugreports and patches :)
Regards,
-octo
-- 
Florian octo Forster
Hacker in training
GnuPG: 0x91523C3D
http://verplant.org/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://mailman.verplant.org/pipermail/collectd/attachments/20070619/b4766e66/attachment.pgp 


More information about the collectd mailing list