about summary refs log tree commit diff
diff options
context:
space:
mode:
authorAlexander Monakov <amonakov@ispras.ru>2017-06-30 00:35:33 +0300
committerRich Felker <dalias@aerifal.cx>2017-09-04 16:38:03 -0400
commit51bdcdc424bd7169c8cccdc2de7cad17f5ea0f70 (patch)
tree9f4ac96baee6d9f0fcc3a6e245743f05232e772e
parentcc0dbd5f09337c187156fe8b697245e6ea9263d0 (diff)
downloadmusl-51bdcdc424bd7169c8cccdc2de7cad17f5ea0f70.tar.gz
musl-51bdcdc424bd7169c8cccdc2de7cad17f5ea0f70.tar.xz
musl-51bdcdc424bd7169c8cccdc2de7cad17f5ea0f70.zip
fix OOB reads in Xbyte_memmem
Reported by Leah Neukirchen.
-rw-r--r--src/string/memmem.c18
1 files changed, 9 insertions, 9 deletions
diff --git a/src/string/memmem.c b/src/string/memmem.c
index 4be6a310..54a66e46 100644
--- a/src/string/memmem.c
+++ b/src/string/memmem.c
@@ -5,27 +5,27 @@
 static char *twobyte_memmem(const unsigned char *h, size_t k, const unsigned char *n)
 {
 	uint16_t nw = n[0]<<8 | n[1], hw = h[0]<<8 | h[1];
-	for (h++, k--; k; k--, hw = hw<<8 | *++h)
-		if (hw == nw) return (char *)h-1;
-	return 0;
+	for (h+=2, k-=2; k; k--, hw = hw<<8 | *h++)
+		if (hw == nw) return (char *)h-2;
+	return hw == nw ? (char *)h-2 : 0;
 }
 
 static char *threebyte_memmem(const unsigned char *h, size_t k, const unsigned char *n)
 {
 	uint32_t nw = n[0]<<24 | n[1]<<16 | n[2]<<8;
 	uint32_t hw = h[0]<<24 | h[1]<<16 | h[2]<<8;
-	for (h+=2, k-=2; k; k--, hw = (hw|*++h)<<8)
-		if (hw == nw) return (char *)h-2;
-	return 0;
+	for (h+=3, k-=3; k; k--, hw = (hw|*h++)<<8)
+		if (hw == nw) return (char *)h-3;
+	return hw == nw ? (char *)h-3 : 0;
 }
 
 static char *fourbyte_memmem(const unsigned char *h, size_t k, const unsigned char *n)
 {
 	uint32_t nw = n[0]<<24 | n[1]<<16 | n[2]<<8 | n[3];
 	uint32_t hw = h[0]<<24 | h[1]<<16 | h[2]<<8 | h[3];
-	for (h+=3, k-=3; k; k--, hw = hw<<8 | *++h)
-		if (hw == nw) return (char *)h-3;
-	return 0;
+	for (h+=4, k-=4; k; k--, hw = hw<<8 | *h++)
+		if (hw == nw) return (char *)h-4;
+	return hw == nw ? (char *)h-4 : 0;
 }
 
 #define MAX(a,b) ((a)>(b)?(a):(b))