Possible memory corruption with user and role names

Bug #1370740 reported by Roberta Marton
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Trafodion
Fix Released
Medium
Cliff Gray

Bug Description

The person that designed and implemented this function did not include a length parameter on purpose. The intention that only the cli GET_SESSION calls and ComUser class will call these functions. Both these places do check for lengths. However, to avoid issues going forward, more care is needed to avoid memory overruns in case someone calls this function with an incorrect buffer size.

Tags: sql-security
Revision history for this message
Roberta Marton (roberta-marton) wrote :

Forgot to mention the functions - it is part of the authQuery mechanism found in Context.cpp

Changed in trafodion:
importance: Undecided → Medium
assignee: nobody → Cliff Gray (cliff-gray)
tags: added: sql-security
Paul Low (paul-low-x)
Changed in trafodion:
milestone: none → r1.1
Cliff Gray (cliff-gray)
Changed in trafodion:
status: New → In Progress
Revision history for this message
Cliff Gray (cliff-gray) wrote :

Fix is ready, will deliver when r1.0 is complete.

Revision history for this message
Cliff Gray (cliff-gray) wrote :

Fix delivered in 1082.

Changed in trafodion:
status: In Progress → Fix Committed
Paul Low (paul-low-x)
Changed in trafodion:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.