Skip to content

false positive: Uncontrolled data used in OS command #199

Open
@ktsaou

Description

@ktsaou

Hi,

We just started using https://github.com/firehol/netdata in LGTM. Thank you!

We found that LGTM reports cpp/command-line-injection false positives.

Here is a screenshot:

image

But the code is the other way around: We use fgets() after we run the command, to read the output of the program we execute, like this:

https://lgtm.com/projects/g/firehol/netdata/snapshot/2a7cf3528a14cd50a69af4d75e1441a4b035d231/files/src/cgroup-network.c?#xb0514f82e375bcb6:1

image

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions