git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 01/12] read_object_with_reference: don't read beyond the buffer

From
MKMartin Koegler <mkoegler@auto.tuwien.ac.at>
Date
Feb 18, 2008, 20:47 UTC
Message-ID
<12033676833730-git-send-email-mkoegler@auto.tuwien.ac.at>
Signed-off-by: Martin Koegler <mkoegler@auto.tuwien.ac.at>
---
 sha1_file.c |    3 ++-
 1 files changed, 2 insertions(+), 1 deletions(-)
diff --git a/sha1_file.c b/sha1_file.c
index 4179949..d9da7c8 100644
--- a/sha1_file.c
+++ b/sha1_file.c
@@ -1943,7 +1943,8 @@ void *read_object_with_reference(const unsigned char *sha1,
 		}
 		ref_length = strlen(ref_type);
 
-		if (memcmp(buffer, ref_type, ref_length) ||
+		if (ref_length + 40 > isize ||
+		    memcmp(buffer, ref_type, ref_length) ||
 		    get_sha1_hex((char *) buffer + ref_length, actual_sha1)) {
 			free(buffer);
 			return NULL;
-- 
1.5.4.1.g96b77
Next: Martin Koegler
Message 1 of 13 in “read_object_with_reference: don't read beyond the buffer”
  1. 01/12 read_object_with_reference: don't read beyond the bufferMartin Koegler, Feb 18, 2008
  2. 02/12 get_sha1_oneline: check return value of parse_objectMartin Koegler, Feb 18, 2008
  3. 03/12 mark_blob/tree_uninteresting: check for NULLMartin Koegler, Feb 18, 2008
  4. 04/12 add_one_tree: handle NULL from lookup_treeMartin Koegler, Feb 18, 2008
  5. 05/12 process_tree/blob: check for NULLMartin Koegler, Feb 18, 2008
  6. 06/12 check results of parse_commit in merge_basesMartin Koegler, Feb 18, 2008
  7. 07/12 peel_onion: handle NULLMartin Koegler, Feb 18, 2008
  8. 08/12 process_tag: handle tag->tagged == NULLMartin Koegler, Feb 18, 2008
  9. 09/12 process_tree/blob: check for NULLMartin Koegler, Feb 18, 2008
  10. 10/12 revision.c: handle tag->tagged == NULLMartin Koegler, Feb 18, 2008
  11. 11/12 parse_commit: don't fail, if object is NULLMartin Koegler, Feb 18, 2008
  12. 12/12 check return value from parse_commitMartin Koegler, Feb 18, 2008
  13. Junio C HamanoFeb 19, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.