| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,4 @@ | |||
| 1 | + Fix a buffer overflow the ``xmlcharrefreplace`` error handler of 8-bit | ||
| 2 | + encoding (such as ``ascii`` and ``latin1``). Previously, a buffer overflow | ||
| 3 | + of one NUL byte was written in the stack memory if the output length was | ||
| 4 | + exactly 512 bytes. Patch by Victor Stinner. | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,4 @@ | |||
| 1 | + Fix a buffer overflow in the ``xmlcharrefreplace`` error handler of 8-bit | ||
| 2 | + encoding (such as ``ascii`` and ``latin1``). Previously, a buffer overflow | ||
| 3 | + wrote one NUL byte in the stack memory if the output length was exactly 512 | ||
| 4 | + bytes. Patch by Victor Stinner. | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -879,10 +879,16 @@ xmlcharrefreplace(PyBytesWriter *writer, char *str, | |||
| 879 | 879 | ||
| 880 | 880 | /* generate replacement */ | |
| 881 | 881 | for (i = collstart; i < collend; ++i) { | |
| 882 | - size = sprintf(str, "&#%d;", PyUnicode_READ(kind, data, i)); | ||
| 883 | - if (size < 0) { | ||
| 884 | - return NULL; | ||
| 885 | - } | ||
| 882 | + // Use snprintf() with a temporary buffer to not write the trailing | ||
| 883 | + // NUL byte in the writer buffer. | ||
| 884 | + Py_BUILD_ASSERT(_Py_MAX_UNICODE <= 0x10ffff); | ||
| 885 | + // len('\0') is 11 bytes. | ||
| 886 | + char buffer[11]; | ||
| 887 | + Py_UCS4 ch = PyUnicode_READ(kind, data, i); | ||
| 888 | + size = snprintf(buffer, sizeof(buffer), "&#%d;", ch); | ||
| 889 | + assert(5 <= size && (size_t)size <= (sizeof(buffer) - 1)); | ||
| 890 | + | ||
| 891 | + memcpy(str, buffer, size); | ||
| 886 | 892 | str += size; | |
| 887 | 893 | } | |
| 888 | 894 | return str; | |
| Back | FazBrowse Home | New Git URL |
0 commit comments