FR-AD-001 - (v2) use strncmp() instead of memcmp() for bounded data
authorAlan T. DeKok <aland@freeradius.org>
Wed, 5 Jul 2017 15:27:35 +0000 (11:27 -0400)
committerAlan T. DeKok <aland@freeradius.org>
Mon, 17 Jul 2017 12:21:57 +0000 (08:21 -0400)
src/main/conffile.c

index 002cfbc..af42baa 100644 (file)
@@ -811,7 +811,7 @@ static const char *cf_expand_variables(const char *cf, int *lineno,
                        p += strlen(p);
                        ptr = end + 1;
 
-               } else if (memcmp(ptr, "$ENV{", 5) == 0) {
+               } else if (strncmp(ptr, "$ENV{", 5) == 0) {
                        char *env;
 
                        ptr += 5;