Browse Source

parse_tag_buffer: don't parse invalid tags

The current tag parsing code can access memory outside the tag buffer,
if \n are missing. This patch prevent this behaviour.

Signed-off-by: Martin Koegler <mkoegler@auto.tuwien.ac.at>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
maint
Martin Koegler 17 years ago committed by Junio C Hamano
parent
commit
a0393ef676
  1. 5
      tag.c

5
tag.c

@ -39,6 +39,7 @@ int parse_tag_buffer(struct tag *item, void *data, unsigned long size)
unsigned char sha1[20]; unsigned char sha1[20];
const char *type_line, *tag_line, *sig_line; const char *type_line, *tag_line, *sig_line;
char type[20]; char type[20];
const char *start = data;


if (item->object.parsed) if (item->object.parsed)
return 0; return 0;
@ -53,11 +54,11 @@ int parse_tag_buffer(struct tag *item, void *data, unsigned long size)
if (memcmp("\ntype ", type_line-1, 6)) if (memcmp("\ntype ", type_line-1, 6))
return -1; return -1;


tag_line = strchr(type_line, '\n'); tag_line = memchr(type_line, '\n', size - (type_line - start));
if (!tag_line || memcmp("tag ", ++tag_line, 4)) if (!tag_line || memcmp("tag ", ++tag_line, 4))
return -1; return -1;


sig_line = strchr(tag_line, '\n'); sig_line = memchr(tag_line, '\n', size - (tag_line - start));
if (!sig_line) if (!sig_line)
return -1; return -1;
sig_line++; sig_line++;

Loading…
Cancel
Save