131c9a
diff -ru cronie-1.5.2/anacron/readtab.c cronie-1.5.2_patched/anacron/readtab.c
131c9a
--- cronie-1.5.2/anacron/readtab.c	2017-09-14 13:53:21.000000000 +0200
131c9a
+++ cronie-1.5.2_patched/anacron/readtab.c	2018-09-07 15:13:17.752498050 +0200
131c9a
@@ -134,8 +134,19 @@
131c9a
 
131c9a
     var_len = (int)strlen(env_var);
131c9a
     val_len = (int)strlen(value);
131c9a
+    if (!var_len) {
131c9a
+        return;
131c9a
+    }
131c9a
+
131c9a
     er = obstack_alloc(&tab_o, sizeof(env_rec));
131c9a
+    if (er == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
+
131c9a
     er->assign = obstack_alloc(&tab_o, var_len + 1 + val_len + 1);
131c9a
+    if (er->assign == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
     strcpy(er->assign, env_var);
131c9a
     er->assign[var_len] = '=';
131c9a
     strcpy(er->assign + var_len + 1, value);
131c9a
@@ -167,15 +178,24 @@
131c9a
 	return;
131c9a
     }
131c9a
     jr = obstack_alloc(&tab_o, sizeof(job_rec));
131c9a
+    if (jr == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
     jr->period = period;
131c9a
     jr->named_period = 0;
131c9a
     delay += random_number;
131c9a
     jr->delay = delay;
131c9a
     jr->tab_line = line_num;
131c9a
     jr->ident = obstack_alloc(&tab_o, ident_len + 1);
131c9a
+    if (jr->ident == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
     strcpy(jr->ident, ident);
131c9a
     jr->arg_num = job_arg_num(ident);
131c9a
     jr->command = obstack_alloc(&tab_o, command_len + 1);
131c9a
+    if (jr->command == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
     strcpy(jr->command, command);
131c9a
     jr->job_pid = jr->mailer_pid = 0;
131c9a
     if (last_job_rec != NULL) last_job_rec->next = jr;
131c9a
@@ -208,6 +228,9 @@
131c9a
     }
131c9a
 
131c9a
     jr = obstack_alloc(&tab_o, sizeof(job_rec));
131c9a
+    if (jr == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
     if (!strncmp ("@monthly", periods, 8)) {
131c9a
 		jr->named_period = 1;
131c9a
     } else if (!strncmp("@yearly", periods, 7) || !strncmp("@annually", periods, 9) || !strncmp(/* backwards compat misspelling */"@annualy", periods, 8)) {
131c9a
@@ -225,9 +248,15 @@
131c9a
     jr->delay = delay;
131c9a
     jr->tab_line = line_num;
131c9a
     jr->ident = obstack_alloc(&tab_o, ident_len + 1);
131c9a
+    if (jr->ident == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
     strcpy(jr->ident, ident);
131c9a
     jr->arg_num = job_arg_num(ident);
131c9a
     jr->command = obstack_alloc(&tab_o, command_len + 1);
131c9a
+    if (jr->command == NULL) {
131c9a
+        die_e("Cannot allocate memory.");
131c9a
+    }
131c9a
     strcpy(jr->command, command);
131c9a
     jr->job_pid = jr->mailer_pid = 0;
131c9a
     if (last_job_rec != NULL) last_job_rec->next = jr;
131c9a
diff -ru cronie-1.5.2/anacron/runjob.c cronie-1.5.2_patched/anacron/runjob.c
131c9a
--- cronie-1.5.2/anacron/runjob.c	2018-01-24 17:02:33.000000000 +0100
131c9a
+++ cronie-1.5.2_patched/anacron/runjob.c	2018-09-07 15:13:17.752498050 +0200
131c9a
@@ -104,9 +104,44 @@
131c9a
 static void
131c9a
 xputenv(const char *s)
131c9a
 {
131c9a
-    char *copy = strdup (s);
131c9a
-    if (!copy) die_e("Not enough memory to set the environment");
131c9a
-    if (putenv(copy)) die_e("Can't set the environment");
131c9a
+    char *name = NULL, *val = NULL;
131c9a
+    char *eq_ptr;
131c9a
+    const char *errmsg;
131c9a
+    size_t eq_index;
131c9a
+
131c9a
+    if (s == NULL) {
131c9a
+        die_e("Invalid environment string");
131c9a
+    }
131c9a
+
131c9a
+    eq_ptr = strchr(s, '=');
131c9a
+    if (eq_ptr == NULL) {
131c9a
+        die_e("Invalid environment string");
131c9a
+    }
131c9a
+
131c9a
+    eq_index = (size_t) (eq_ptr - s);
131c9a
+
131c9a
+    name = malloc((eq_index + 1) * sizeof(char));
131c9a
+    if (name == NULL) {
131c9a
+        die_e("Not enough memory to set the environment");
131c9a
+    }
131c9a
+
131c9a
+    val = malloc((strlen(s) - eq_index) * sizeof(char));
131c9a
+    if (val == NULL) {
131c9a
+        die_e("Not enough memory to set the environment");
131c9a
+    }
131c9a
+
131c9a
+    strncpy(name, s, eq_index);
131c9a
+    name[eq_index] = '\0';
131c9a
+    strcpy(val, s + eq_index + 1);
131c9a
+
131c9a
+    if (setenv(name, val, 1)) {
131c9a
+        die_e("Can't set the environment");
131c9a
+    }
131c9a
+
131c9a
+    free(name);
131c9a
+    free(val);
131c9a
+    return;
131c9a
+
131c9a
 }
131c9a
 
131c9a
 static void
131c9a
diff -ru cronie-1.5.2/src/entry.c cronie-1.5.2_patched/src/entry.c
131c9a
--- cronie-1.5.2/src/entry.c	2017-09-14 13:53:21.000000000 +0200
131c9a
+++ cronie-1.5.2_patched/src/entry.c	2018-09-07 15:13:17.752498050 +0200
131c9a
@@ -131,8 +131,10 @@
131c9a
 			goto eof;
131c9a
 		}
131c9a
 		ch = get_char(file);
131c9a
-		if (ch == EOF)
131c9a
+		if (ch == EOF) {
131c9a
+			free(e);
131c9a
 			return NULL;
131c9a
+		}
131c9a
 	}
131c9a
 
131c9a
 	if (ch == '@') {