upstream: Allow for different (but POSIX compliant) behaviour of
basename(3) and prevent a use-after-free in that case in the new sftp-compat code. POSIX allows basename(3) to either return a pointer to static storage or modify the passed string and return a pointer to that. OpenBSD does the former and works as is, but on other platforms "filename" points into "tmp" which was just freed. This makes the freeing of tmp consistent with the other variable in the loop. Pinpointed by the -portable Valgrind regress test. ok djm@ deraadt@ OpenBSD-Commit-ID: 750f3c19bd4440e4210e30dd5d7367386e833374
This commit is contained in:
parent
6df1fecb5d
commit
911ec64118
7
scp.c
7
scp.c
|
@ -1,4 +1,4 @@
|
||||||
/* $OpenBSD: scp.c,v 1.216 2021/08/02 23:38:27 djm Exp $ */
|
/* $OpenBSD: scp.c,v 1.217 2021/08/04 01:34:55 dtucker Exp $ */
|
||||||
/*
|
/*
|
||||||
* scp - secure remote copy. This is basically patched BSD rcp which
|
* scp - secure remote copy. This is basically patched BSD rcp which
|
||||||
* uses ssh to do the data transfer (instead of using rcmd).
|
* uses ssh to do the data transfer (instead of using rcmd).
|
||||||
|
@ -1461,11 +1461,9 @@ sink_sftp(int argc, char *dst, const char *src, struct sftp_conn *conn)
|
||||||
tmp = xstrdup(g.gl_pathv[i]);
|
tmp = xstrdup(g.gl_pathv[i]);
|
||||||
if ((filename = basename(tmp)) == NULL) {
|
if ((filename = basename(tmp)) == NULL) {
|
||||||
error("basename %s: %s", tmp, strerror(errno));
|
error("basename %s: %s", tmp, strerror(errno));
|
||||||
free(tmp);
|
|
||||||
err = -1;
|
err = -1;
|
||||||
goto out;
|
goto out;
|
||||||
}
|
}
|
||||||
free(tmp);
|
|
||||||
|
|
||||||
if (local_is_dir(dst))
|
if (local_is_dir(dst))
|
||||||
abs_dst = path_append(dst, filename);
|
abs_dst = path_append(dst, filename);
|
||||||
|
@ -1484,10 +1482,13 @@ sink_sftp(int argc, char *dst, const char *src, struct sftp_conn *conn)
|
||||||
}
|
}
|
||||||
free(abs_dst);
|
free(abs_dst);
|
||||||
abs_dst = NULL;
|
abs_dst = NULL;
|
||||||
|
free(tmp);
|
||||||
|
tmp = NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
out:
|
out:
|
||||||
free(abs_src);
|
free(abs_src);
|
||||||
|
free(tmp);
|
||||||
globfree(&g);
|
globfree(&g);
|
||||||
if (err == -1) {
|
if (err == -1) {
|
||||||
fatal("Failed to download file '%s'", src);
|
fatal("Failed to download file '%s'", src);
|
||||||
|
|
Loading…
Reference in New Issue