klocwork Null ptr deref in softoken/pk11db.c

RESOLVED FIXED in 3.12

Status

NSS
Libraries
P2
normal
RESOLVED FIXED
11 years ago
11 years ago

People

(Reporter: Nelson Bolyard (seldom reads bugmail), Assigned: Alexei Volkov)

Tracking

({klocwork})

trunk
3.12
klocwork

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment, 1 obsolete attachment)

1.47 KB, patch
Nelson Bolyard (seldom reads bugmail)
: review+
Details | Diff | Splinter Review
Klocwork ID 88483
Function: secmod_getSecmodName
Location: nss/lib/softoken/pk11db.c : 286

Pointer 'configdir' returned from call to function 'secmod_argFetchValue' 
at line 271 may be NULL and will be dereferenced by passing argument 1 to 
function 'sftk_EvaluateConfigDir' at line 286.

270	    while (*param) { 
271		SECMOD_HANDLE_STRING_ARG(param,configdir,"configDir=",;) 
272		SECMOD_HANDLE_STRING_ARG(param,secmodName,"secmod=",;) 
273		SECMOD_HANDLE_FINAL_ARG(param) 
274	   } 
286	   lconfigdir = sftk_EvaluateConfigDir(configdir, appName);
(Reporter)

Updated

11 years ago
Priority: -- → P2
Target Milestone: --- → 3.12
(Assignee)

Comment 1

11 years ago
Created attachment 242935 [details] [diff] [review]
check a pointer for NULL before calling sftk_EvaluateConfigDir
Assignee: nobody → alexei.volkov.bugs
Status: NEW → ASSIGNED
Attachment #242935 - Flags: review?(nelson)
(Reporter)

Comment 2

11 years ago
Comment on attachment 242935 [details] [diff] [review]
check a pointer for NULL before calling sftk_EvaluateConfigDir

>-   lconfigdir = sftk_EvaluateConfigDir(configdir, appName);
>+   if (configdir) {
>+       lconfigdir = sftk_EvaluateConfigDir(configdir, appName);
>+   }
>    if (lconfigdir) {

lconfigdir is uninitialized, so value is random if !confidir.
Attachment #242935 - Flags: review?(nelson) → review-
(Assignee)

Comment 3

11 years ago
Created attachment 243410 [details] [diff] [review]
init lconfigdir
Attachment #242935 - Attachment is obsolete: true
Attachment #243410 - Flags: review?(nelson)
(Reporter)

Comment 4

11 years ago
Comment on attachment 243410 [details] [diff] [review]
init lconfigdir

r=nelson
Attachment #243410 - Flags: review?(nelson) → review+
(Assignee)

Comment 5

11 years ago
/cvsroot/mozilla/security/nss/lib/softoken/pk11db.c,v  <--  pk11db.c
new revision: 1.38; previous revision: 1.37
Status: ASSIGNED → RESOLVED
Last Resolved: 11 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.