提交 32d67e93 编写于 作者: R Rich Felker

fix twos complement overflow bug in mem streams boundary check

the expression -off is not safe in case off is the most-negative
value. instead apply - to base which is known to be non-negative and
bounded within sanity.
上级 d4fa6f0e
......@@ -28,7 +28,7 @@ static off_t ms_seek(FILE *f, off_t off, int whence)
errno = EINVAL;
return -1;
}
if (-off > base || off > SSIZE_MAX-base) goto fail;
if (off < -base || off > SSIZE_MAX-base) goto fail;
return c->pos = base+off;
}
......
......@@ -29,7 +29,7 @@ static off_t wms_seek(FILE *f, off_t off, int whence)
errno = EINVAL;
return -1;
}
if (-off > base || off > SSIZE_MAX/4-base) goto fail;
if (off < -base || off > SSIZE_MAX/4-base) goto fail;
memset(&c->mbs, 0, sizeof c->mbs);
return c->pos = base+off;
}
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册