Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer overrun in FileHandleReadLine()

2020-08-26 Thread Vladimir Olovyannikov via groups.io
..@intel.com; > >> vladimir.olovyanni...@broadcom.com > >> Cc: Kinney, Michael D ; Gao, Liming > >> > >> Subject: Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: > >> fix buffer overrun in FileHandleReadLine() > >> > >> On 0

Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer overrun in FileHandleReadLine()

2020-08-26 Thread Laszlo Ersek
ao, Liming >> >> Subject: Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix >> buffer overrun in FileHandleReadLine() >> >> On 08/24/20 18:18, Laszlo Ersek wrote: >>> On 07/03/20 04:30, Zhiguang Liu wrote: >>>> Reviewed-by: Zhiguang

Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer overrun in FileHandleReadLine()

2020-08-24 Thread Vladimir Olovyannikov via groups.io
ikov via groups.io > >>> Sent: Thursday, July 2, 2020 10:31 AM > >>> To: devel@edk2.groups.io > >>> Cc: Vladimir Olovyannikov ; > >>> Kinney, Michael D ; Gao, Liming > >>> ; Liu, Zhiguang > >>> Subject: [edk2-deve

Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer overrun in FileHandleReadLine()

2020-08-24 Thread Laszlo Ersek
Olovyannikov via groups.io >>> Sent: Thursday, July 2, 2020 10:31 AM >>> To: devel@edk2.groups.io >>> Cc: Vladimir Olovyannikov ; Kinney, >>> Michael D ; Gao, Liming >>> ; Liu, Zhiguang >>> Subject: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib

Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer overrun in FileHandleReadLine()

2020-08-24 Thread Laszlo Ersek
yannikov via groups.io >> Sent: Thursday, July 2, 2020 10:31 AM >> To: devel@edk2.groups.io >> Cc: Vladimir Olovyannikov ; Kinney, >> Michael D ; Gao, Liming >> ; Liu, Zhiguang >> Subject: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer >>

Re: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer overrun in FileHandleReadLine()

2020-07-02 Thread Zhiguang Liu
Liu, Zhiguang > Subject: [edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer > overrun in FileHandleReadLine() > > If the size of the supplied buffer in FileHandleReadLine(), module > UefiFileHandleLib.c, was not 0, but was not enough to fit in > the line,

[edk2-devel] [PATCH v2 1/1] MdePkg : UefiFileHandleLib: fix buffer overrun in FileHandleReadLine()

2020-07-01 Thread Vladimir Olovyannikov via groups.io
If the size of the supplied buffer in FileHandleReadLine(), module UefiFileHandleLib.c, was not 0, but was not enough to fit in the line, the size is increased, and then the Buffer of the new size is zeroed. This size is always larger than the supplied buffer size, causing supplied buffer overrun.