Menu

#1 Wipe password in shmysql.c

open
nobody
None
5
2007-10-15
2007-10-15
No

Wrong number of chars in string comparasion

diff -ruN

--- shmysql.c.old 2005-01-31 20:35:27.000000000 +0100
+++ shmysql.c 2007-10-15 11:16:53.000000000 +0200
@@ -190,7 +190,7 @@
for(i=1;i<argc;i++)
{
string_cat(str, argv[i]);
- if((!strncasecmp(argv[i], "password", 9))
+ if((!strncasecmp(argv[i], "password", 8))
|| (!strncasecmp(argv[i], "user", 4))
|| (!strncasecmp(argv[i], "username", 8)))
wipe(argv[i]);

Discussion


Log in to post a comment.