mirror of
https://github.com/curl/curl.git
synced 2026-08-24 23:43:40 +03:00
wildcardmatch: fix heap buffer overflow in setcharset
The code would previous read beyond the end of the pattern string if the match pattern ends with an open bracket when the default pattern matching function is used. Detected by OSS-Fuzz: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=4161 CVE-2017-8817 Bug: https://curl.haxx.se/docs/adv_2017-ae72.html
This commit is contained in:
parent
9b5e12a549
commit
0b664ba968
3 changed files with 56 additions and 7 deletions
|
|
@ -133,6 +133,9 @@ static int setcharset(unsigned char **p, unsigned char *charset)
|
|||
unsigned char c;
|
||||
for(;;) {
|
||||
c = **p;
|
||||
if(!c)
|
||||
return SETCHARSET_FAIL;
|
||||
|
||||
switch(state) {
|
||||
case CURLFNM_SCHS_DEFAULT:
|
||||
if(ISALNUM(c)) { /* ASCII value */
|
||||
|
|
@ -196,9 +199,6 @@ static int setcharset(unsigned char **p, unsigned char *charset)
|
|||
else
|
||||
return SETCHARSET_FAIL;
|
||||
}
|
||||
else if(c == '\0') {
|
||||
return SETCHARSET_FAIL;
|
||||
}
|
||||
else {
|
||||
charset[c] = 1;
|
||||
(*p)++;
|
||||
|
|
@ -274,9 +274,6 @@ static int setcharset(unsigned char **p, unsigned char *charset)
|
|||
else if(c == ']') {
|
||||
return SETCHARSET_OK;
|
||||
}
|
||||
else if(c == '\0') {
|
||||
return SETCHARSET_FAIL;
|
||||
}
|
||||
else if(ISPRINT(c)) {
|
||||
charset[c] = 1;
|
||||
(*p)++;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue