Bug 181415
Summary: | sscanf (glibc) read data overrun found with valgrind | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 4 | Reporter: | Phil Blanchfield <phil.blanchfield> |
Component: | glibc | Assignee: | Jakub Jelinek <jakub> |
Status: | CLOSED NOTABUG | QA Contact: | Brian Brock <bbrock> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 4.0 | CC: | drepper |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | i686 | ||
OS: | Linux | ||
URL: | ftp://ftp.crc.ca/crc/ravs/sscanf_bug.c | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2006-02-13 21:39:07 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Phil Blanchfield
2006-02-13 21:24:38 UTC
That testcase is invalid. See ISO C99 7.19.6.7. The first argument to sscanf is string, rather than a char array. Now, 7.1.1 says that a string is a contiguous sequence of characters terminated by and including the first null character. In your testcase you don't pass a string pointer as the first sscanf argument, but a pointer to character array, not terminated by null. |