2010/12/7 Eric Blake <eblake@xxxxxxxxxx>: > * src/openvz/openvz_conf.c (openvzLoadDomains): Replace unsafe > sscanf with safe direct parsing. > (openvzGetVEID): Avoid lost integer overflow detection. > (openvzAssignUUIDs): Likewise, and detect readdir failure. > --- > > v2: new patch; plugs a potential security hole, since > *scanf("%s",fixed_width_buffer) is exploitable, but the > exploit could only happen if /usr/sbin/vzlist is compromised. > > Âsrc/openvz/openvz_conf.c | Â 39 +++++++++++++++++++++++++-------------- > Â1 files changed, 25 insertions(+), 14 deletions(-) > ACK. Matthias -- libvir-list mailing list libvir-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/libvir-list