tool_operate: return error on strdup() failure

In src/tool_operate.c inside the Windows safe-search branch (#ifdef
CURL_CA_SEARCH_SAFE), the code assigns config->cacert = strdup(cacert);
at line 2076 without checking whether strdup returned NULL.

This would allow the code to continue with the wrong value set, causing
possible confusion.

Pointed out by ZeroPath
Closes #19145
This commit is contained in:
Daniel Stenberg 2025-10-19 16:12:56 +02:00
parent 7f19fa9819
commit 4c636b2dc1
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2

View file

@ -2072,6 +2072,10 @@ static CURLcode cacertpaths(struct OperationConfig *config)
if(cafile) {
curlx_fclose(cafile);
config->cacert = strdup(cacert);
if(!config->cacert) {
result = CURLE_OUT_OF_MEMORY;
goto fail;
}
}
#elif !defined(CURL_WINDOWS_UWP) && !defined(UNDER_CE) && \
!defined(CURL_DISABLE_CA_SEARCH)