diff options
author | Serhiy Storchaka <storchaka@gmail.com> | 2015-09-04 04:48:19 (GMT) |
---|---|---|
committer | Serhiy Storchaka <storchaka@gmail.com> | 2015-09-04 04:48:19 (GMT) |
commit | 4e63f7a2b4e3602c420c8ae59a16020b14f8ee13 (patch) | |
tree | d9767697d27b578b7bd7cd9cd9e789a541736553 /Modules | |
parent | df6b544ff6f342e8a64056e627867a70413bfdb0 (diff) | |
download | cpython-4e63f7a2b4e3602c420c8ae59a16020b14f8ee13.zip cpython-4e63f7a2b4e3602c420c8ae59a16020b14f8ee13.tar.gz cpython-4e63f7a2b4e3602c420c8ae59a16020b14f8ee13.tar.bz2 |
Issue #24989: Fixed buffer overread in BytesIO.readline() if a position is
set beyond size. Based on patch by John Leitch.
Diffstat (limited to 'Modules')
-rw-r--r-- | Modules/_io/bytesio.c | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/Modules/_io/bytesio.c b/Modules/_io/bytesio.c index d46430d..31cc1f7 100644 --- a/Modules/_io/bytesio.c +++ b/Modules/_io/bytesio.c @@ -57,14 +57,18 @@ scan_eol(bytesio *self, Py_ssize_t len) Py_ssize_t maxlen; assert(self->buf != NULL); + assert(self->pos >= 0); + + if (self->pos >= self->string_size) + return 0; /* Move to the end of the line, up to the end of the string, s. */ - start = PyBytes_AS_STRING(self->buf) + self->pos; maxlen = self->string_size - self->pos; if (len < 0 || len > maxlen) len = maxlen; if (len) { + start = PyBytes_AS_STRING(self->buf) + self->pos; n = memchr(start, '\n', len); if (n) /* Get the length from the current position to the end of |