diff options
author | Jim Meyering <jim@meyering.net> | 2011-05-20 19:20:12 +0200 |
---|---|---|
committer | Junio C Hamano <gitster@pobox.com> | 2011-05-20 20:39:49 +0200 |
commit | 42536dd9b9829b4eb4e3706e141b3c8bffa3e826 (patch) | |
tree | db640fa331f2b513c593eda286400c2086c9ec5a /diff.c | |
parent | t4034 (diff --word-diff): add a minimum Perl drier test vector (diff) | |
download | git-42536dd9b9829b4eb4e3706e141b3c8bffa3e826.tar.xz git-42536dd9b9829b4eb4e3706e141b3c8bffa3e826.zip |
do not read beyond end of malloc'd buffer
With diff.suppress-blank-empty=true, "git diff --word-diff" would
output data that had been read from uninitialized heap memory.
The problem was that fn_out_consume did not account for the
possibility of a line with length 1, i.e., the empty context line
that diff.suppress-blank-empty=true converts from " \n" to "\n".
Since it assumed there would always be a prefix character (the space),
it decremented "len" unconditionally, thus passing len=0 to emit_line,
which would then blindly call emit_line_0 with len=-1 which would
pass that value on to fwrite as SIZE_MAX. Boom.
Signed-off-by: Jim Meyering <meyering@redhat.com>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
Diffstat (limited to 'diff.c')
-rw-r--r-- | diff.c | 12 |
1 files changed, 10 insertions, 2 deletions
@@ -1043,8 +1043,16 @@ static void fn_out_consume(void *priv, char *line, unsigned long len) emit_line(ecbdata->opt, plain, reset, line, len); fputs("~\n", ecbdata->opt->file); } else { - /* don't print the prefix character */ - emit_line(ecbdata->opt, plain, reset, line+1, len-1); + /* + * Skip the prefix character, if any. With + * diff_suppress_blank_empty, there may be + * none. + */ + if (line[0] != '\n') { + line++; + len--; + } + emit_line(ecbdata->opt, plain, reset, line, len); } return; } |