kdepim buffers patch

Adriaan de Groot groot at kde.org
Mon Jan 3 17:06:49 GMT 2005


On Friday 31 December 2004 21:44, Steve G wrote:
> I was using Korganizer to look at an .ics file and it crashed. I
> investigated the problem and found that a buffer was not big enough to hold
> the text being created via sprintf. The fact that sprintf was being used
> and not snprintf caused a great deal of concern since kdepim handles files
> from untrusted sources.

The libical/ and versit/ fixes have been applied now, along with the fix to 
kholidays. Lots of stuff has moved around, so your patch didn't apply 
straightforawrdly.

Then there's all the gpgme patches in there, which you didn't comment on and 
which I'm not going to commit (not my turf and more pointedly, turf with real 
security implications that I don't want to think about).


-- 
Don't worry, 't ain't no shame to be stupid - ol' mouse.
    GPG: FEA2 A3FE Adriaan de Groot
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
URL: <http://mail.kde.org/pipermail/kde-core-devel/attachments/20050103/3cc9a10e/attachment.sig>
-------------- next part --------------
_______________________________________________
kde-pim mailing list
kde-pim at kde.org
https://mail.kde.org/mailman/listinfo/kde-pim
kde-pim home page at http://pim.kde.org/


More information about the kde-core-devel mailing list