Hello All,
In reviewing code in MariaDB 10.0.2x, I found an instance where
a memory request via strndup() is made, but no check for a return
value of NULL, indicating failure is made. The directory in this
case is 'mariadb-10.0.20/plugin/auth_pam/' and the filename is
'auth_pam.c'. The patch file below should address this issue:
--- auth_pam.c.orig 2015-08-23 16:16:25.075000000 -0700
|
+++ auth_pam.c 2015-08-23 16:18:17.594000000 -0700
|
@@ -99,6 +99,9 @@
|
return PAM_CONV_ERR;
|
/* allocate and copy the reply to the response array */
|
(*resp)[i].resp = strndup((char*)pkt, pkt_len);
|
+ if ( (*resp)[i].resp == NULL) {
|
+ return PAM_CONV_ERR;
|
+ }
|
param->ptr = param->buf + 1;
|
}
|
}
|
Questions, Comments, Suggestions?
I am attaching the patch file(s) to this bug report.
Bill Parker (wp02855 at gmail dot com)
{"report":{"fcp":997.7000007629395,"ttfb":187.10000038146973,"pageVisibility":"visible","entityId":52804,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"4b994251-dd5d-40b1-b3ec-c80b16da89a3","navigationType":0,"readyForUser":1164.8000001907349,"redirectCount":0,"resourceLoadedEnd":1220.1000003814697,"resourceLoadedStart":194.4000005722046,"resourceTiming":[{"duration":247.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":194.4000005722046,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":194.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":441.9000005722046,"responseStart":0,"secureConnectionStart":0},{"duration":247.5999994277954,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":194.70000076293945,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":194.70000076293945,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":442.30000019073486,"responseStart":0,"secureConnectionStart":0},{"duration":260.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":194.80000019073486,"connectEnd":194.80000019073486,"connectStart":194.80000019073486,"domainLookupEnd":194.80000019073486,"domainLookupStart":194.80000019073486,"fetchStart":194.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":194.80000019073486,"responseEnd":455.5,"responseStart":455.5,"secureConnectionStart":194.80000019073486},{"duration":331.1000003814697,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":195.10000038146973,"connectEnd":195.10000038146973,"connectStart":195.10000038146973,"domainLookupEnd":195.10000038146973,"domainLookupStart":195.10000038146973,"fetchStart":195.10000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":195.10000038146973,"responseEnd":526.2000007629395,"responseStart":526.2000007629395,"secureConnectionStart":195.10000038146973},{"duration":334.8999996185303,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":195.4000005722046,"connectEnd":195.4000005722046,"connectStart":195.4000005722046,"domainLookupEnd":195.4000005722046,"domainLookupStart":195.4000005722046,"fetchStart":195.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":195.4000005722046,"responseEnd":530.3000001907349,"responseStart":530.3000001907349,"secureConnectionStart":195.4000005722046},{"duration":335.80000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":195.5,"connectEnd":195.5,"connectStart":195.5,"domainLookupEnd":195.5,"domainLookupStart":195.5,"fetchStart":195.5,"redirectEnd":0,"redirectStart":0,"requestStart":195.5,"responseEnd":531.3000001907349,"responseStart":531.3000001907349,"secureConnectionStart":195.5},{"duration":342.0999994277954,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":195.70000076293945,"connectEnd":195.70000076293945,"connectStart":195.70000076293945,"domainLookupEnd":195.70000076293945,"domainLookupStart":195.70000076293945,"fetchStart":195.70000076293945,"redirectEnd":0,"redirectStart":0,"requestStart":195.70000076293945,"responseEnd":537.8000001907349,"responseStart":537.8000001907349,"secureConnectionStart":195.70000076293945},{"duration":417.30000019073486,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":196,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":196,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":613.3000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":342.5,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":196.10000038146973,"connectEnd":196.10000038146973,"connectStart":196.10000038146973,"domainLookupEnd":196.10000038146973,"domainLookupStart":196.10000038146973,"fetchStart":196.10000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":196.10000038146973,"responseEnd":538.6000003814697,"responseStart":538.6000003814697,"secureConnectionStart":196.10000038146973},{"duration":417.19999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":196.30000019073486,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":196.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":613.5,"responseStart":0,"secureConnectionStart":0},{"duration":343.0999994277954,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":196.4000005722046,"connectEnd":196.4000005722046,"connectStart":196.4000005722046,"domainLookupEnd":196.4000005722046,"domainLookupStart":196.4000005722046,"fetchStart":196.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":196.4000005722046,"responseEnd":539.5,"responseStart":539.4000005722046,"secureConnectionStart":196.4000005722046},{"duration":838.1999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":197.30000019073486,"connectEnd":197.30000019073486,"connectStart":197.30000019073486,"domainLookupEnd":197.30000019073486,"domainLookupStart":197.30000019073486,"fetchStart":197.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":197.30000019073486,"responseEnd":1035.5,"responseStart":1035.5,"secureConnectionStart":197.30000019073486},{"duration":861.6999998092651,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":197.4000005722046,"connectEnd":197.4000005722046,"connectStart":197.4000005722046,"domainLookupEnd":197.4000005722046,"domainLookupStart":197.4000005722046,"fetchStart":197.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":197.4000005722046,"responseEnd":1059.1000003814697,"responseStart":1059.1000003814697,"secureConnectionStart":197.4000005722046},{"duration":332.29999923706055,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":627.7000007629395,"connectEnd":627.7000007629395,"connectStart":627.7000007629395,"domainLookupEnd":627.7000007629395,"domainLookupStart":627.7000007629395,"fetchStart":627.7000007629395,"redirectEnd":0,"redirectStart":0,"requestStart":627.7000007629395,"responseEnd":960,"responseStart":960,"secureConnectionStart":627.7000007629395},{"duration":246.79999923706055,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":985.7000007629395,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":985.7000007629395,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1232.5,"responseStart":0,"secureConnectionStart":0},{"duration":211,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":1009.1000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1009.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1220.1000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":154.79999923706055,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":1010.2000007629395,"connectEnd":1010.2000007629395,"connectStart":1010.2000007629395,"domainLookupEnd":1010.2000007629395,"domainLookupStart":1010.2000007629395,"fetchStart":1010.2000007629395,"redirectEnd":0,"redirectStart":0,"requestStart":1010.2000007629395,"responseEnd":1165,"responseStart":1165,"secureConnectionStart":1010.2000007629395},{"duration":186.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/097ae97cb8fbec7d6ea4bbb1f26955b9-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":1011.1000003814697,"connectEnd":1011.1000003814697,"connectStart":1011.1000003814697,"domainLookupEnd":1011.1000003814697,"domainLookupStart":1011.1000003814697,"fetchStart":1011.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":1011.1000003814697,"responseEnd":1197.3000001907349,"responseStart":1197.3000001907349,"secureConnectionStart":1011.1000003814697}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":8,"responseStart":187,"responseEnd":188,"domLoading":192,"domInteractive":1277,"domContentLoadedEventStart":1277,"domContentLoadedEventEnd":1329,"domComplete":2461,"loadEventStart":2461,"loadEventEnd":2463,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1246.9000005722046},{"name":"bigPipe.sidebar-id.end","time":1247.9000005722046},{"name":"bigPipe.activity-panel-pipe-id.start","time":1248},{"name":"bigPipe.activity-panel-pipe-id.end","time":1250.8000001907349},{"name":"activityTabFullyLoaded","time":1341.7000007629395}],"measures":[],"correlationId":"42ef786ebb1af5","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":104,"dbReadsTimeInMs":14,"dbConnsTimeInMs":24,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}