telephony: ijx: buffer overflow in ixj_write_cid()
authorDan Carpenter <dan.carpenter@oracle.com>
Mon, 3 Dec 2012 19:05:12 +0000 (22:05 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 17 Dec 2012 18:49:03 +0000 (10:49 -0800)
commitd2e08635c22a9222f606062b42a7ad656f6a8584
tree8cdb9a5a59e76bd01ecdf64cf92e093fc4e7b6cd
parentcde5ccfd7fff61f9b652dc7b42a40168e3e45f93
telephony: ijx: buffer overflow in ixj_write_cid()

[Not needed in 3.8 or newer as this driver is removed there. - gregkh]

We get this from user space and nothing has been done to ensure that
these strings are NUL terminated.

Reported-by: Chen Gang <gang.chen@asianux.com>
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/telephony/ixj.c