summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSerhiy Storchaka <storchaka@gmail.com>2017-02-04 20:53:57 (GMT)
committerSerhiy Storchaka <storchaka@gmail.com>2017-02-04 20:53:57 (GMT)
commit7e10dbbd45503268f7bb3b241e30745df6c91b99 (patch)
treef85d0be894a656f4c6dd473030a3e69ad9cddd6f
parentc7611362b425277da80b2397e0abedee58138996 (diff)
downloadcpython-7e10dbbd45503268f7bb3b241e30745df6c91b99.zip
cpython-7e10dbbd45503268f7bb3b241e30745df6c91b99.tar.gz
cpython-7e10dbbd45503268f7bb3b241e30745df6c91b99.tar.bz2
Issue #29444: Fixed out-of-bounds buffer access in the group() method of
the match object. Based on patch by WGH.
-rw-r--r--Lib/test/test_re.py10
-rw-r--r--Misc/NEWS3
-rw-r--r--Modules/_sre.c9
3 files changed, 20 insertions, 2 deletions
diff --git a/Lib/test/test_re.py b/Lib/test/test_re.py
index 0834fe0..9acd5ab 100644
--- a/Lib/test/test_re.py
+++ b/Lib/test/test_re.py
@@ -1679,6 +1679,16 @@ SUBPATTERN None
self.checkPatternError(r'(?<>)', 'unknown extension ?<>', 1)
self.checkPatternError(r'(?', 'unexpected end of pattern', 2)
+ def test_bug_29444(self):
+ s = bytearray(b'abcdefgh')
+ m = re.search(b'[a-h]+', s)
+ m2 = re.search(b'[e-h]+', s)
+ self.assertEqual(m.group(), b'abcdefgh')
+ self.assertEqual(m2.group(), b'efgh')
+ s[:] = b'xyz'
+ self.assertEqual(m.group(), b'xyz')
+ self.assertEqual(m2.group(), b'')
+
class PatternReprTests(unittest.TestCase):
def check(self, pattern, expected):
diff --git a/Misc/NEWS b/Misc/NEWS
index 898b1a3..55303a5 100644
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -21,6 +21,9 @@ Extension Modules
Library
-------
+- Issue #29444: Fixed out-of-bounds buffer access in the group() method of
+ the match object. Based on patch by WGH.
+
- Issue #29335: Fix subprocess.Popen.wait() when the child process has
exited to a stopped instead of terminated state (ex: when under ptrace).
diff --git a/Modules/_sre.c b/Modules/_sre.c
index 09b5835..4b376ec 100644
--- a/Modules/_sre.c
+++ b/Modules/_sre.c
@@ -2015,6 +2015,7 @@ match_getslice_by_index(MatchObject* self, Py_ssize_t index, PyObject* def)
Py_buffer view;
PyObject *result;
void* ptr;
+ Py_ssize_t i, j;
if (index < 0 || index >= self->groups) {
/* raise IndexError if we were given a bad group number */
@@ -2036,8 +2037,12 @@ match_getslice_by_index(MatchObject* self, Py_ssize_t index, PyObject* def)
ptr = getstring(self->string, &length, &isbytes, &charsize, &view);
if (ptr == NULL)
return NULL;
- result = getslice(isbytes, ptr,
- self->string, self->mark[index], self->mark[index+1]);
+
+ i = self->mark[index];
+ j = self->mark[index+1];
+ i = Py_MIN(i, length);
+ j = Py_MIN(j, length);
+ result = getslice(isbytes, ptr, self->string, i, j);
if (isbytes && view.buf != NULL)
PyBuffer_Release(&view);
return result;