Commit ed1f4ab1 authored by Rob Swindell's avatar Rob Swindell 💬
Browse files

Initialize time zone variable (zone)

As found and reported by Talisam author, apam (HAPPYLND).

sscanf() won't initialize the buffer of the argument passed if the format string is not matched, so when there was no hexadecimal/SMB timezone value, the timezone specified in the ISO date/time string (if any) would be overwritten with 0, converted from the uninitialized 'zone' variable (unlikely to be valid hex-ASCII chars). Thanks apam!
parent 47bb6691
Pipeline #2469 passed with stage
in 14 minutes and 29 seconds
......@@ -26,7 +26,7 @@
static bool qwk_parse_header_list(sbbs_t* sbbs, ulong confnum, smbmsg_t* msg, str_list_t* headers, bool parse_sender_hfields, bool parse_recipient_hfields)
char* p;
char zone[32];
char zone[32] = "";
char value[INI_MAX_VALUE_LEN+1];
int i;
uint16_t net_type;
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment