core-agent-linux/qubes-rpc
Vincent Penquerc'h 38c0ea3128 qopen-in-vm: fix read overflow
That one would also send more data to the other VM that what we
intended: the start of the env var data (which in similar code
on my host includes the GPG agent socket path, XDG session cookie,
and more.

The other side expects a fixed size though, so pad with NULs.

Interestingly, the original code was not vulnerable as it was
callocing enough space.
2014-01-06 17:57:40 +01:00
..
.gitignore The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
dvm2.h The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
gui-fatal.c The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
gui-fatal.h The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
ioall.c core-agent-linux: misc const fixups 2014-01-06 17:57:40 +01:00
ioall.h The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
Makefile Restore qfile-agent compilation 2013-11-09 18:58:46 +01:00
prepare-suspend suspend: empty default list of modules to unload 2013-10-24 04:13:27 +02:00
qfile-agent.c qfile-utils: fix global variables declarations 2013-11-09 19:00:37 +01:00
qfile-unpacker.c qfile-unpacker: some error checking 2014-01-06 17:57:40 +01:00
qfile-utils.c tar2qfile: ignore EDQUOT error from dom0 2013-11-09 19:04:24 +01:00
qfile-utils.h qfile-utils: fix global variables declarations 2013-11-09 19:00:37 +01:00
qopen-in-vm.c qopen-in-vm: fix read overflow 2014-01-06 17:57:40 +01:00
qrun-in-vm The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.Backup Add qubes.{Backup,Restore} services, include them in rpm package 2013-11-09 19:01:57 +01:00
qubes.DetachPciDevice Add qubes.DetachPciDevice for live PCI detach (#708) 2013-09-01 01:28:07 +02:00
qubes.Filecopy The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.Filecopy.policy The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.GetAppmenus The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.OpenInVM The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.OpenInVM.policy The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.Restore minor whitespace fix 2013-11-24 04:45:36 +01:00
qubes.SuspendPost The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.SuspendPre The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.SyncNtpClock The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.VMShell The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.VMShell.policy The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qubes.WaitForSession Hide errors from qubes.WaitForSession 2013-12-15 05:36:43 +01:00
qvm-copy-gnome.desktop The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qvm-copy-to-vm qvm-copy-to-vm: implement --ignore-symlinks option 2013-08-14 22:12:46 +02:00
qvm-copy-to-vm.gnome qvm-copy-to-vm: implement --ignore-symlinks option 2013-08-14 22:12:46 +02:00
qvm-copy-to-vm.kde qvm-copy-to-vm: implement --ignore-symlinks option 2013-08-14 22:12:46 +02:00
qvm-copy.desktop The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qvm-dvm-gnome.desktop The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qvm-dvm.desktop The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qvm-mru-entry The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
qvm-open-in-dvm The Underscores Revolution: adjust qrexec path 2013-03-14 04:29:19 +01:00
qvm-open-in-vm qvm-open-in-vm: fix path for URL wrapper 2013-11-14 21:37:16 +01:00
qvm-run The Underscores Revolution: adjust qrexec path 2013-03-14 04:29:19 +01:00
sync-ntp-clock The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00
tar2qfile.c tar2qfile: use lseek() to skip unwanted data if possible 2013-11-25 02:28:35 +01:00
vm-file-editor.c vm-file-editor: add override for mimeinfo *.png entry (#753) 2013-11-14 22:21:17 +01:00
wrap-in-html-if-url.sh The Underscores Revolution: RPC services 2013-03-14 04:25:31 +01:00