Menu

#310 osafamfnd crashes for various bad input

4.2.5
fixed
nobody
None
defect
amf
-
4.2.2
major
2013-09-09
2013-05-24
No

Migrated from http://devel.opensaf.org/ticket/3020

amfnd needs to be hardened for bad input for obvious security reasons. List of issues found so far:

  • avnd_mds_dec/avnd_mds_flat_dec: osafassert in case default
  • avnd_mds_flat_ava_dec: seg fault since msg size not checked
  • avnd_mds_rcv: osafassert in case default
  • avnd_evt_destroy: osafassert in case default

Related

Tickets: #310

Discussion

  • Hans Feldt

    Hans Feldt - 2013-06-17
    • status: unassigned --> accepted
    • assigned_to: Hans Feldt
     
  • Hans Feldt

    Hans Feldt - 2013-06-17
     
  • Hans Feldt

    Hans Feldt - 2013-08-09
    • status: accepted --> review
    • Milestone: future --> 4.2.5
     
  • Hans Feldt

    Hans Feldt - 2013-08-28
    • status: review --> fixed
    • assigned_to: Hans Feldt --> nobody
     
  • Hans Feldt

    Hans Feldt - 2013-08-28

    [opensaf-4.2.x:4440]
    [opensaf-4.3.x:4441]
    [default:4442]

     
  • Hans Feldt

    Hans Feldt - 2013-08-28

    [default:92a727b73152]
    hg tip --template '[{branch}:{node|short}]\n'

     
  • Hans Feldt

    Hans Feldt - 2013-08-28

    [default:92a727]
    testing...

     
  • Hans Feldt

    Hans Feldt - 2013-08-28
     

    Related

    Commit: [92a727]

  • Hans Feldt

    Hans Feldt - 2013-08-28

    Developers please exec the following command before push and paste the output into the ticket:

    $ changes=$(hg outg --template '{node}\n' | egrep -v comparing|searching | cut -c -6); for c in $changes; do echo "[staging:$c]"; done

    This will create hyperlinks between the artifact (ticket) and the mercurial repository.

    We need to come up with some mercurial pre push hook that does this automatically.

     
  • Anders Bjornerstedt

    This information needs to go int tools/devel/review.
    Perhaps the commit.template whatever that is.

    Just having it an old mail is a bit too loose.

    /AndersBj


    From: Hans Feldt [mailto:hansfeldt@users.sf.net]
    Sent: den 28 augusti 2013 09:44
    To: [opensaf:tickets]
    Subject: [tickets] [opensaf:tickets] #310 osafamfnd crashes for various bad input

    Developers please exec the following command before push and paste the output into the ticket:

    $ changes=$(hg outg --template '{node}\n' | egrep -v comparing|searching | cut -c -6); for c in $changes; do echo "[staging:$c]"; done

    This will create hyperlinks between the artifact (ticket) and the mercurial repository.

    We need to come up with some mercurial pre push hook that does this automatically.


    [tickets:#310]http://sourceforge.net/p/opensaf/tickets/310/ osafamfnd crashes for various bad input

    Status: fixed
    Created: Fri May 24, 2013 08:25 AM UTC by Nagendra Kumar
    Last Updated: Wed Aug 28, 2013 07:35 AM UTC
    Owner: nobody

    Migrated from http://devel.opensaf.org/ticket/3020

    amfnd needs to be hardened for bad input for obvious security reasons. List of issues found so far:

    • avnd_mds_dec/avnd_mds_flat_dec: osafassert in case default
    • avnd_mds_flat_ava_dec: seg fault since msg size not checked
    • avnd_mds_rcv: osafassert in case default
    • avnd_evt_destroy: osafassert in case default

    Sent from sourceforge.net because opensaf-tickets@lists.sourceforge.net is subscribed to https://sourceforge.net/p/opensaf/tickets/

    To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/opensaf/admin/tickets/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.

     

    Related

    Tickets: #310
    Tickets: tickets


Log in to post a comment.