diff options
author | dgp <dgp@users.sourceforge.net> | 2017-05-05 19:11:33 (GMT) |
---|---|---|
committer | dgp <dgp@users.sourceforge.net> | 2017-05-05 19:11:33 (GMT) |
commit | 435fd1ab8b987021ad8a7220a1f4fc89c3a4c872 (patch) | |
tree | 69cc278dc4f56de87c60196da9f49f1092ec866b /generic | |
parent | aa7f26cefe717461f284fb9e389ee6a613b2d970 (diff) | |
parent | 509ac989d9ace73fcc8da899b7ea70fc3bd8c1d7 (diff) | |
download | tcl-435fd1ab8b987021ad8a7220a1f4fc89c3a4c872.zip tcl-435fd1ab8b987021ad8a7220a1f4fc89c3a4c872.tar.gz tcl-435fd1ab8b987021ad8a7220a1f4fc89c3a4c872.tar.bz2 |
[6015221f59] Segfault after overflow of [binary] field specifier numeric count.
Diffstat (limited to 'generic')
-rw-r--r-- | generic/tclBinary.c | 10 |
1 files changed, 9 insertions, 1 deletions
diff --git a/generic/tclBinary.c b/generic/tclBinary.c index a3e5071..72f1498 100644 --- a/generic/tclBinary.c +++ b/generic/tclBinary.c @@ -1743,7 +1743,15 @@ GetFormatSpec( (*formatPtr)++; *countPtr = BINARY_ALL; } else if (isdigit(UCHAR(**formatPtr))) { /* INTL: digit */ - *countPtr = strtoul(*formatPtr, (char **) formatPtr, 10); + unsigned long int count; + + errno = 0; + count = strtoul(*formatPtr, (char **) formatPtr, 10); + if (errno || (count > (unsigned long) INT_MAX)) { + *countPtr = INT_MAX; + } else { + *countPtr = (int) count; + } } else { *countPtr = BINARY_NOCOUNT; } |