From 6be73862186f958638776b7b8545f26f7010f97b Mon Sep 17 00:00:00 2001 From: matz Date: Mon, 14 Apr 2008 03:58:35 +0000 Subject: * array.c (ary_new): new integer overflow check condition. suggested by TOYOFUKU Chikanobu in [ruby-dev:34156]. * array.c (rb_ary_initialize): ditto. git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/trunk@15997 b2dd03c8-39d4-4d8f-98ff-823fe69b080e --- ChangeLog | 8 ++++++++ array.c | 4 ++-- 2 files changed, 10 insertions(+), 2 deletions(-) diff --git a/ChangeLog b/ChangeLog index ce29a6b0da..bc1a24b391 100644 --- a/ChangeLog +++ b/ChangeLog @@ -6,6 +6,14 @@ Mon Apr 14 12:52:25 2008 Nobuyoshi Nakada * gc.c (finalizers): removed. [ruby-dev:34349] +Mon Apr 14 11:30:07 2008 Yukihiro Matsumoto + + * array.c (ary_new): new integer overflow check condition. + suggested by TOYOFUKU Chikanobu in + [ruby-dev:34156]. + + * array.c (rb_ary_initialize): ditto. + Mon Apr 14 00:51:40 2008 Yusuke Endoh * test/ruby/test_parse.rb: add tests to achieve over 95% test coverage diff --git a/array.c b/array.c index 8ccbd97ff1..edbc35d4b0 100644 --- a/array.c +++ b/array.c @@ -114,7 +114,7 @@ ary_new(VALUE klass, long len) if (len < 0) { rb_raise(rb_eArgError, "negative array size (or size too big)"); } - if (len > 0 && len * (long)sizeof(VALUE) <= len) { + if (len > LONG_MAX / sizeof(VALUE)) { rb_raise(rb_eArgError, "array size too big"); } ary = ary_alloc(klass); @@ -313,7 +313,7 @@ rb_ary_initialize(int argc, VALUE *argv, VALUE ary) if (len < 0) { rb_raise(rb_eArgError, "negative array size"); } - if (len > 0 && len * (long)sizeof(VALUE) <= len) { + if (len > LONG_MAX / sizeof(VALUE)) { rb_raise(rb_eArgError, "array size too big"); } rb_ary_modify(ary); -- cgit v1.2.3