...
In a hosted environment, the main function receives a third argument,
char *envp[]
, that points to a null-terminated array of pointers tochar
, each of which points to a string that provides information about the environment for this execution of the program.
Consequently, under a hosted environment it is possible to access the environment through a modified form of main()
:
...
After a call to the POSIX setenv()
function, or another function that modifies the environment, the envp
pointer may no longer reference the environment. POSIX states that [Open Group 2004]
unanticipated results may occur if
setenv()
changes the external variableenviron
. In particular, if the optionalenvp
argument tomain()
is present, it is not changed, and as a result may point to an obsolete copy of the environment (as may any other copy ofenviron
).
...
Because envp
may no longer point to the current environment, this program has undefined behavior.
Compliant Solution (POSIX)
...
According to the Visual C++ reference [MSDN],
The environment block passed to
main
andwmain
is a "frozen" copy of the current environment. If you subsequently change the environment via a call toputenv
or_wputenv
, the current environment (as returned bygetenv
/_wgetenv
and the_environ
/_wenviron
variable) will change, but the block pointed to byenvp
will not change.
...
Tool | Version | Checker | Description | ||||||
---|---|---|---|---|---|---|---|---|---|
Compass/ROSE |
|
|
| ||||||
PRQA QA-C |
| 0601 (E) | Fully implemented |
Related Vulnerabilities
...
ISO/IEC 9899:2011 Section J.5.1, "Environment arguments"
Bibliography
[MSDN] getenv, _wgetenv
, _environ, _wenviron
, _putenv_s, _wputenv_s
[Open Group 2004] setenv()
...