aboutsummaryrefslogtreecommitdiff
path: root/src/appl
diff options
context:
space:
mode:
authorTom Yu <tlyu@mit.edu>2007-12-14 05:14:11 +0000
committerTom Yu <tlyu@mit.edu>2007-12-14 05:14:11 +0000
commit7427af6b5cbb849398cf6bf05f2f7a4385e57840 (patch)
tree6a91446f3dcedc240b03bdaa4447e562a29f6a5b /src/appl
parent01b3b9cbb23f8e8790ba0daeac24667c4f9f34ea (diff)
downloadkrb5-7427af6b5cbb849398cf6bf05f2f7a4385e57840.zip
krb5-7427af6b5cbb849398cf6bf05f2f7a4385e57840.tar.gz
krb5-7427af6b5cbb849398cf6bf05f2f7a4385e57840.tar.bz2
fix CVE-2007-5894: apparent uninit length in ftpd.c:reply()
ticket: 5853 target_version: 1.6.4 tags: pullup git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@20182 dc483132-0cff-0310-8789-dd5450dbe970
Diffstat (limited to 'src/appl')
-rw-r--r--src/appl/gssftp/ftpd/ftpd.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/appl/gssftp/ftpd/ftpd.c b/src/appl/gssftp/ftpd/ftpd.c
index 708bfde..9d33260 100644
--- a/src/appl/gssftp/ftpd/ftpd.c
+++ b/src/appl/gssftp/ftpd/ftpd.c
@@ -1812,7 +1812,7 @@ reply(n, fmt, p0, p1, p2, p3, p4, p5)
* radix_encode, gss_seal, plus slop.
*/
char in[FTP_BUFSIZ*3/2], out[FTP_BUFSIZ*3/2];
- int length, kerror;
+ int length = 0, kerror;
if (n) sprintf(in, "%d%c", n, cont_char);
else in[0] = '\0';
strncat(in, buf, sizeof (in) - strlen(in) - 1);