fix CVE-2007-5894: apparent uninit length in ftpd.c:reply()
authorTom Yu <tlyu@mit.edu>
Fri, 14 Dec 2007 05:14:11 +0000 (05:14 +0000)
committerTom Yu <tlyu@mit.edu>
Fri, 14 Dec 2007 05:14:11 +0000 (05:14 +0000)
ticket: 5853
target_version: 1.6.4
tags: pullup

git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@20182 dc483132-0cff-0310-8789-dd5450dbe970

src/appl/gssftp/ftpd/ftpd.c

index 708bfde93d266dc126763cd096085dc2478eaaa6..9d332608c06682f90a6f41b7c9befd8ded535394 100644 (file)
@@ -1812,7 +1812,7 @@ reply(n, fmt, p0, p1, p2, p3, p4, p5)
                 * radix_encode, gss_seal, plus slop.
                 */
                char in[FTP_BUFSIZ*3/2], out[FTP_BUFSIZ*3/2];
-               int length, kerror;
+               int length = 0, kerror;
                if (n) sprintf(in, "%d%c", n, cont_char);
                else in[0] = '\0';
                strncat(in, buf, sizeof (in) - strlen(in) - 1);