diff options
author | usa <usa@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2018-03-28 14:38:39 +0000 |
---|---|---|
committer | usa <usa@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2018-03-28 14:38:39 +0000 |
commit | 4cd92d7b13002161a3452a0fe278b877901a8859 (patch) | |
tree | eda6ad9c89109d491eb523057485eabe5719d18a | |
parent | 47165eed264d357e78e27371cfef20d5c2bde5d9 (diff) |
merge revision(s) 62992:
pack.c: fix underflow
* pack.c (pack_unpack_internal): get rid of underflow.
https://hackerone.com/reports/298246
git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/branches/ruby_2_2@63019 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
-rw-r--r-- | ChangeLog | 7 | ||||
-rw-r--r-- | pack.c | 2 | ||||
-rw-r--r-- | test/ruby/test_pack.rb | 3 | ||||
-rw-r--r-- | version.h | 2 |
4 files changed, 12 insertions, 2 deletions
@@ -1,3 +1,10 @@ +Wed Mar 28 23:37:18 2018 Nobuyoshi Nakada <nobu@ruby-lang.org> + + pack.c: fix underflow + + * pack.c (pack_unpack_internal): get rid of underflow. + https://hackerone.com/reports/298246 + Wed Mar 28 23:35:28 2018 Nobuyoshi Nakada <nobu@ruby-lang.org> unixsocket.c: check NUL bytes @@ -1203,7 +1203,7 @@ pack_unpack(VALUE str, VALUE fmt) else if (ISDIGIT(*p)) { errno = 0; len = STRTOUL(p, (char**)&p, 10); - if (errno) { + if (len < 0 || errno) { rb_raise(rb_eRangeError, "pack length too big"); } } diff --git a/test/ruby/test_pack.rb b/test/ruby/test_pack.rb index 18f71e4a2f..449911198c 100644 --- a/test/ruby/test_pack.rb +++ b/test/ruby/test_pack.rb @@ -480,6 +480,9 @@ class TestPack < Test::Unit::TestCase assert_equal([1, 2], "\x01\x00\x00\x02".unpack("C@3C")) assert_equal([nil], "\x00".unpack("@1C")) # is it OK? assert_raise(ArgumentError) { "\x00".unpack("@2C") } + + pos = (1 << [nil].pack("p").bytesize * 8) - 100 # -100 + assert_raise(RangeError) {"0123456789".unpack("@#{pos}C10")} end def test_pack_unpack_percent @@ -1,6 +1,6 @@ #define RUBY_VERSION "2.2.10" #define RUBY_RELEASE_DATE "2018-03-28" -#define RUBY_PATCHLEVEL 485 +#define RUBY_PATCHLEVEL 486 #define RUBY_RELEASE_YEAR 2018 #define RUBY_RELEASE_MONTH 3 |