[OpenWrt-Devel] [PATCH] [netifd] vlan: Array out of bounds in snprintf for vlans

Daniel F. Dickinson cshored at thecshore.com
Thu Feb 1 06:54:21 EST 2018

On 01/02/18 02:29 AM, Daniel F. Dickinson wrote:
> On 31/01/18 06:20 AM, Paul Oranje wrote:
>> Why use a hard coded value 4 in "snprintf(devnum, 4, "%d", vldev->id);" ?
>> Paul

Oh I see this also the uglier first throw-together; there is a v2 that 
isn't as bad (and is actually right; this version actually is wrong but 
I tested the wrong thing (short end not long end), and didn't notice the 
issue until I came back and reviewed for titch longer.


