git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 4/4] Fix integer overflow in unpack_compressed_entry()

From
ILIlari Liusvaara <ilari.liusvaara@elisanet.fi>
Date
Jan 26, 2010, 18:24 UTC
Message-ID
<1264530255-4682-5-git-send-email-ilari.liusvaara@elisanet.fi>
In-Reply-To
<1264530255-4682-1-git-send-email-ilari.liusvaara@elisanet.fi>
Signed-off-by: Ilari Liusvaara <ilari.liusvaara@elisanet.fi>
---
 sha1_file.c |    3 +--
 1 files changed, 1 insertions(+), 2 deletions(-)
diff --git a/sha1_file.c b/sha1_file.c
index 39f0844..ea2ea75 100644
--- a/sha1_file.c
+++ b/sha1_file.c
@@ -1517,8 +1517,7 @@ static void *unpack_compressed_entry(struct packed_git *p,
 	z_stream stream;
 	unsigned char *buffer, *in;
 
-	buffer = xmalloc(size + 1);
-	buffer[size] = 0;
+	buffer = xmallocz(size);
 	memset(&stream, 0, sizeof(stream));
 	stream.next_out = buffer;
 	stream.avail_out = size + 1;
-- 
1.6.6.1.439.gf06b6
Previous: Ilari LiusvaaraNext: Junio C Hamano
Message 10 of 13 in “Fix various integer overflows”
  1. 0/4 Fix various integer overflowsIlari Liusvaara, Jan 26, 2010
  2. 1/4 Add xmallocz()Ilari Liusvaara, Jan 26, 2010
  3. Bill LearJan 26, 2010
  4. Junio C HamanoJan 26, 2010
  5. Junio C HamanoJan 26, 2010
  6. Ilari LiusvaaraJan 26, 2010
  7. Bill LearJan 26, 2010
  8. 2/4 Fix integer overflow in patch_delta()Ilari Liusvaara, Jan 26, 2010
  9. 3/4 Fix integer overflow in unpack_sha1_rest()Ilari Liusvaara, Jan 26, 2010
  10. 4/4 Fix integer overflow in unpack_compressed_entry()Ilari Liusvaara, Jan 26, 2010
  11. Junio C HamanoJan 26, 2010
  12. Stephen R. van den BergJan 27, 2010
  13. Ilari LiusvaaraJan 27, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.