From fd934e1187952ef6227dae8caaddd881782cc323 Mon Sep 17 00:00:00 2001 From: Peter Stephenson Date: Fri, 19 Dec 2014 21:54:37 +0000 Subject: 34005: region_highlights memory fix Zero uninitialised part of memory when reallocing --- Src/Zle/zle_refresh.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) (limited to 'Src/Zle/zle_refresh.c') diff --git a/Src/Zle/zle_refresh.c b/Src/Zle/zle_refresh.c index 9f8075386..c146e46eb 100644 --- a/Src/Zle/zle_refresh.c +++ b/Src/Zle/zle_refresh.c @@ -399,6 +399,7 @@ get_region_highlight(UNUSED(Param pm)) if (!arrsize) return hmkarray(NULL); arrsize -= N_SPECIAL_HIGHLIGHTS; + DPUTS(arrsize < 0, "arrsize is negative from n_region_highlights"); arrp = retarr = (char **)zhalloc((arrsize+1)*sizeof(char *)); /* ignore special highlighting */ @@ -450,10 +451,15 @@ set_region_highlight(UNUSED(Param pm), char **aval) len = aval ? arrlen(aval) : 0; if (n_region_highlights != len + N_SPECIAL_HIGHLIGHTS) { /* no null termination, but include special highlighting at start */ - n_region_highlights = len + N_SPECIAL_HIGHLIGHTS; + int newsize = len + N_SPECIAL_HIGHLIGHTS; + int diffsize = newsize - n_region_highlights; region_highlights = (struct region_highlight *) zrealloc(region_highlights, - sizeof(struct region_highlight) * n_region_highlights); + sizeof(struct region_highlight) * newsize); + if (diffsize > 0) + memset(region_highlights + newsize, 0, + sizeof(struct region_highlight) * diffsize); + n_region_highlights = newsize; } if (!aval) -- cgit 1.4.1