From: Marc Hoersken Date: Sat, 19 Apr 2014 13:23:04 +0000 (+0200) Subject: telnet.c: check sscanf results before passing them to snprintf X-Git-Tag: curl-7_37_0~132 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=662fc625177208896ce707c5e39ea58d9936cb84;p=thirdparty%2Fcurl.git telnet.c: check sscanf results before passing them to snprintf --- diff --git a/lib/telnet.c b/lib/telnet.c index f8946f4946..1f03a00fc8 100644 --- a/lib/telnet.c +++ b/lib/telnet.c @@ -932,8 +932,8 @@ static void suboption(struct connectdata *conn) size_t len; size_t tmplen; int err; - char varname[128]; - char varval[128]; + char varname[128] = ""; + char varval[128] = ""; struct SessionHandle *data = conn->data; struct TELNET *tn = (struct TELNET *)data->req.protop; @@ -973,11 +973,12 @@ static void suboption(struct connectdata *conn) tmplen = (strlen(v->data) + 1); /* Add the variable only if it fits */ if(len + tmplen < (int)sizeof(temp)-6) { - sscanf(v->data, "%127[^,],%127s", varname, varval); - snprintf((char *)&temp[len], sizeof(temp) - len, - "%c%s%c%s", CURL_NEW_ENV_VAR, varname, - CURL_NEW_ENV_VALUE, varval); - len += tmplen; + if(sscanf(v->data, "%127[^,],%127s", varname, varval)) { + snprintf((char *)&temp[len], sizeof(temp) - len, + "%c%s%c%s", CURL_NEW_ENV_VAR, varname, + CURL_NEW_ENV_VALUE, varval); + len += tmplen; + } } } snprintf((char *)&temp[len], sizeof(temp) - len,