summaryrefslogtreecommitdiffstats
path: root/Python
diff options
context:
space:
mode:
authorINADA Naoki <methane@users.noreply.github.com>2018-07-14 03:06:43 (GMT)
committerGitHub <noreply@github.com>2018-07-14 03:06:43 (GMT)
commit16dfca4d829e45f36e71bf43f83226659ce49315 (patch)
treef06c2f627ae2b4984d1c56ae97248b6eb5c51c38 /Python
parentcafaf0447b950fd4f59edd8cbde040c61ae528f8 (diff)
downloadcpython-16dfca4d829e45f36e71bf43f83226659ce49315.zip
cpython-16dfca4d829e45f36e71bf43f83226659ce49315.tar.gz
cpython-16dfca4d829e45f36e71bf43f83226659ce49315.tar.bz2
bpo-34087: Fix buffer overflow in int(s) and similar functions (GH-8274)
`_PyUnicode_TransformDecimalAndSpaceToASCII()` missed trailing NUL char. It caused buffer overflow in `_Py_string_to_number_with_underscores()`. This bug is introduced in 9b6c60cb.
Diffstat (limited to 'Python')
-rw-r--r--Python/pystrtod.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/Python/pystrtod.c b/Python/pystrtod.c
index 3546d44..461e8dc 100644
--- a/Python/pystrtod.c
+++ b/Python/pystrtod.c
@@ -391,6 +391,8 @@ _Py_string_to_number_with_underscores(
char *dup, *end;
PyObject *result;
+ assert(s[orig_len] == '\0');
+
if (strchr(s, '_') == NULL) {
return innerfunc(s, orig_len, arg);
}