Date: Tue, 9 Mar 2010 21:06:01 +0000 (UTC) From: "Andrey A. Chernov" <ache@FreeBSD.org> To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org Subject: svn commit: r204927 - head/usr.bin/uniq Message-ID: <201003092106.o29L61Ca029911@svn.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: ache Date: Tue Mar 9 21:06:01 2010 New Revision: 204927 URL: http://svn.freebsd.org/changeset/base/204927 Log: Add SIZE_MAX overflow check Modified: head/usr.bin/uniq/uniq.c Modified: head/usr.bin/uniq/uniq.c ============================================================================== --- head/usr.bin/uniq/uniq.c Tue Mar 9 21:01:12 2010 (r204926) +++ head/usr.bin/uniq/uniq.c Tue Mar 9 21:06:01 2010 (r204927) @@ -196,6 +196,8 @@ convert(const char *str) if ((n = mbstowcs(NULL, str, 0)) == (size_t)-1) return (NULL); + if (SIZE_MAX / sizeof(*buf) < n + 1) + errx(1, "conversion buffer length overflow"); if ((buf = malloc((n + 1) * sizeof(*buf))) == NULL) err(1, "malloc"); if (mbstowcs(buf, str, n + 1) != n)
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201003092106.o29L61Ca029911>