OpenSDE Packages Database (without history before r20070)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

51 lines
2.0 KiB

  1. # --- SDE-COPYRIGHT-NOTE-BEGIN ---
  2. # This copyright note is auto-generated by ./scripts/Create-CopyPatch.
  3. #
  4. # Filename: package/.../musl/memmem.patch
  5. # Copyright (C) 2016 The OpenSDE Project
  6. #
  7. # More information can be found in the files COPYING and README.
  8. #
  9. # This patch file is dual-licensed. It is available under the license the
  10. # patched project is licensed under, as long as it is an OpenSource license
  11. # as defined at http://www.opensource.org/ (e.g. BSD, X11) or under the terms
  12. # of the GNU General Public License as published by the Free Software
  13. # Foundation; either version 2 of the License, or (at your option) any later
  14. # version.
  15. # --- SDE-COPYRIGHT-NOTE-END ---
  16. From c718f9fc1b4bd913eff10d0c12763f90b2bc487c Mon Sep 17 00:00:00 2001
  17. From: Rich Felker <dalias@aerifal.cx>
  18. Date: Fri, 1 Apr 2016 13:36:15 -0400
  19. Subject: fix read past end of haystack buffer for short needles in memmem
  20. the two/three/four byte memmem specializations are not prepared to
  21. handle haystacks shorter than the needle; they unconditionally read at
  22. least up to the needle length and subtract from the haystack length.
  23. if the haystack is shorter, the remaining haystack length underflows
  24. and produces an unbounded search which will eventually either crash or
  25. find a spurious match.
  26. the top-level memmem function attempted to avoid this case already by
  27. checking for haystack shorter than needle, but it failed to re-check
  28. after using memchr to remove the maximal prefix not containing the
  29. first byte of the needle.
  30. ---
  31. src/string/memmem.c | 1 +
  32. 1 file changed, 1 insertion(+)
  33. diff --git a/src/string/memmem.c b/src/string/memmem.c
  34. index d7e1221..4be6a31 100644
  35. --- a/src/string/memmem.c
  36. +++ b/src/string/memmem.c
  37. @@ -140,6 +140,7 @@ void *memmem(const void *h0, size_t k, const void *n0, size_t l)
  38. h = memchr(h0, *n, k);
  39. if (!h || l==1) return (void *)h;
  40. k -= h - (const unsigned char *)h0;
  41. + if (k<l) return 0;
  42. if (l==2) return twobyte_memmem(h, k, n);
  43. if (l==3) return threebyte_memmem(h, k, n);
  44. if (l==4) return fourbyte_memmem(h, k, n);
  45. --
  46. cgit v0.11.2