This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: [patch] Fix for heap overflow in wscanf (BZ 16618)


On Mon, Feb 2, 2015 at 11:23 AM, Paul Eggert <eggert@cs.ucla.edu> wrote:

> So, how about the attached (untested) patch to vfscanf.c instead? It's
> simpler.  It does rely on realloc (wp, SIZE_MAX) returning NULL, but that's
> safe in glibc.

I like it. Re-tested.

Combined patch attached.

Thanks,
-- 
Paul Pluzhnikov

2015-02-02  Paul Eggert  <eggert@cs.ucla.edu>
	    Paul Pluzhnikov  <ppluzhnikov@google.com>

	[BZ #16618]
	* stdio-common/vfscanf.c (ADDW): Correct alloca size check and
	fix heap buffer overflow.
	* stdio-common/tst-sscanf.c: Add test for BZ 16618

Attachment: pr16618.patch6.txt
Description: Text document


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]