diff options
author | NARUSE, Yui <naruse@airemix.jp> | 2022-04-12 19:54:07 +0900 |
---|---|---|
committer | NARUSE, Yui <naruse@airemix.jp> | 2022-04-12 19:54:07 +0900 |
commit | 8d142ecff9af7d60728b8cfa9138e8623985c428 (patch) | |
tree | 56e6a4d43a18debab9ee97325684c0cfc2eee74a | |
parent | 73f45e5e96ccc13a131f7c0122cf8600ce5b930f (diff) |
Fix dtoa buffer overrun
-rw-r--r-- | missing/dtoa.c | 3 | ||||
-rw-r--r-- | test/ruby/test_float.rb | 18 |
2 files changed, 20 insertions, 1 deletions
diff --git a/missing/dtoa.c b/missing/dtoa.c index a940eabd91..b7a8302875 100644 --- a/missing/dtoa.c +++ b/missing/dtoa.c @@ -1552,6 +1552,7 @@ break2: if (!*++s || !(s1 = strchr(hexdigit, *s))) goto ret0; if (*s == '0') { while (*++s == '0'); + if (!*s) goto ret; s1 = strchr(hexdigit, *s); } if (s1 != NULL) { @@ -1574,7 +1575,7 @@ break2: for (; *s && (s1 = strchr(hexdigit, *s)); ++s) { adj += aadj * ((s1 - hexdigit) & 15); if ((aadj /= 16) == 0.0) { - while (strchr(hexdigit, *++s)); + while (*++s && strchr(hexdigit, *s)); break; } } diff --git a/test/ruby/test_float.rb b/test/ruby/test_float.rb index 4be2cfeeda..57a46fce92 100644 --- a/test/ruby/test_float.rb +++ b/test/ruby/test_float.rb @@ -171,6 +171,24 @@ class TestFloat < Test::Unit::TestCase assert_raise(ArgumentError, n += z + "A") {Float(n)} assert_raise(ArgumentError, n += z + ".0") {Float(n)} end + + x = nil + 2000.times do + x = Float("0x"+"0"*30) + break unless x == 0.0 + end + assert_equal(0.0, x, ->{"%a" % x}) + x = nil + 2000.times do + begin + x = Float("0x1."+"0"*270) + rescue ArgumentError => e + raise unless /"0x1\.0{270}"/ =~ e.message + else + break + end + end + assert_nil(x, ->{"%a" % x}) end def test_divmod |