This is the mail archive of the binutils@sourceware.org mailing list for the binutils project.
| Index Nav: | [Date Index] [Subject Index] [Author Index] [Thread Index] | |
|---|---|---|
| Message Nav: | [Date Prev] [Date Next] | [Thread Prev] [Thread Next] |
| Other format: | [Raw text] | |
On 10.11.19 05:51, Orlando Arias wrote:
> Greetings
>
> On 11/9/19 6:18 PM, Tim Rühsen wrote:
>> In line
>> if (dirs[num_dirs - 1] == NULL)
>> 'num_dirs' can be 0.
>>
>> Regards, Tim
>>
>
> I've looked at the control-flow on this file and I do not see a possible
> path for num_dirs to be 0 at line 186, unless the file name in question
> is the empty string "", at which point it may just be easier to return
> earlier. Can you please verify this?
Yes, I can confirm. Thanks for review !
Returning early on an empty 'name' also fixes another read overflow in
#ifdef HAVE_DOS_BASED_FILE_SYSTEM
if (name[1] == ':' && IS_DIR_SEPARATOR (name[2]))
{
p += 3;
num_dirs++;
}
#endif /* HAVE_DOS_BASED_FILE_SYSTEM */
Patch v2 appended.
Regards, Tim
From 848cf430c4393555f35f4e4d27da8a555f6308c3 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
Date: Sun, 10 Nov 2019 11:51:00 +0100
Subject: [PATCH] [libiberty] Fix read buffer overflow in split_directories()
* libiberty/make-relative-prefix.c: Return early on empty 'name'
---
libiberty/make-relative-prefix.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/libiberty/make-relative-prefix.c b/libiberty/make-relative-prefix.c
index ec0b0ee749..2ff2af8a59 100644
--- a/libiberty/make-relative-prefix.c
+++ b/libiberty/make-relative-prefix.c
@@ -122,6 +122,9 @@ split_directories (const char *name, int *ptr_num_dirs)
const char *p, *q;
int ch;
+ if (!*name)
+ return NULL;
+
/* Count the number of directories. Special case MSDOS disk names as part
of the initial directory. */
p = name;
--
2.24.0
Attachment:
signature.asc
Description: OpenPGP digital signature
| Index Nav: | [Date Index] [Subject Index] [Author Index] [Thread Index] | |
|---|---|---|
| Message Nav: | [Date Prev] [Date Next] | [Thread Prev] [Thread Next] |