Bug 104146
| Summary: | Fault pointer in "watch" | ||
|---|---|---|---|
| Product: | [Retired] Red Hat Linux | Reporter: | JW <ohtmvyyn> |
| Component: | procps | Assignee: | Daniel Walsh <dwalsh> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Brian Brock <bbrock> |
| Severity: | high | Docs Contact: | |
| Priority: | medium | ||
| Version: | 9 | ||
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2004-02-11 13:42:06 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
This is fixed in 2.0.16, we need to upgrade. *** Bug 106399 has been marked as a duplicate of this bug. *** Eek. Ignore a mistaken dup. Fixed in latest release 3.1.15 |
From Bugzilla Helper: User-Agent: Mozilla/5.0 (compatible; MSIE 5.01; Windows 98;) Description of problem: Here is the code in question: for (; optind < argc; optind++) { int s = strlen(argv[optind]); char *endp = &command[command_length]; *endp = ' '; command_length += s + 1; command = realloc(command, command_length + 1); strcpy(endp + 1, argv[optind]); } Study it carefully. Looks fine doesn't it. Well it isn't. The 'endp' is set to point somewhere in relation to 'command' Then 'command' is changed via realloc. Then 'endp' is used again like nothing has changed! Version-Release number of selected component (if applicable): 2.0.13-8 How reproducible: Always Steps to Reproduce: 1. Read the code 2. 3. Actual Results: Depends on realloc/malloc implementation. At worse segmentation error, but usually just garbled result. Unless your system allocate memory in rather large chunks. Additional info: