[ 
https://issues.apache.org/jira/browse/HADOOP-10733?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14058585#comment-14058585
 ] 

Junping Du commented on HADOOP-10733:
-------------------------------------

+1. Patch looks good. Will commit it shortly.

> Potential null dereference in CredentialShell#promptForCredential()
> -------------------------------------------------------------------
>
>                 Key: HADOOP-10733
>                 URL: https://issues.apache.org/jira/browse/HADOOP-10733
>             Project: Hadoop Common
>          Issue Type: Bug
>            Reporter: Ted Yu
>            Assignee: Ted Yu
>            Priority: Minor
>         Attachments: hadoop-10733-v1.txt
>
>
> {code}
>       char[] newPassword1 = c.readPassword("Enter password: ");
>       char[] newPassword2 = c.readPassword("Enter password again: ");
>       noMatch = !Arrays.equals(newPassword1, newPassword2);
>       if (noMatch) {
>         Arrays.fill(newPassword1, ' ');
> {code}
> newPassword1 might be null, leading to NullPointerException in Arrays.fill() 
> call.
> Similar issue for the following call on line 381:
> {code}
>       Arrays.fill(newPassword2, ' ');
> {code}



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to