# HG changeset patch # User Bruno Haible # Date 1067522944 0 # Node ID d12cca839b2d7f847683053289acc83d8a7d85fa # Parent 82b23fb351ab9c2a13da9a1475b0d289479a0d5a Check for overflow when converting from size_t to 'int'. diff --git a/lib/ChangeLog b/lib/ChangeLog --- a/lib/ChangeLog +++ b/lib/ChangeLog @@ -1,3 +1,9 @@ +2003-10-30 Paul Eggert + Bruno Haible + + * vasprintf.c: Include , . + (vasprintf): Fail if the resulting length doesn't fit in an 'int'. + 2003-10-29 Paul Eggert * xalloc.h (xalloc_oversized): Now a macro, not a function, diff --git a/lib/vasprintf.c b/lib/vasprintf.c --- a/lib/vasprintf.c +++ b/lib/vasprintf.c @@ -1,5 +1,5 @@ /* Formatted output to strings. - Copyright (C) 1999, 2002 Free Software Foundation, Inc. + Copyright (C) 1999, 2002-2003 Free Software Foundation, Inc. This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by @@ -22,6 +22,9 @@ /* Specification. */ #include "vasprintf.h" +#include +#include + #include "vasnprintf.h" int @@ -31,6 +34,14 @@ char *result = vasnprintf (NULL, &length, format, args); if (result == NULL) return -1; + if (length > INT_MAX) + { + /* We could produce such a big string, but can't return its length + as an 'int'. */ + free (result); + return -1; + } + *resultp = result; /* Return the number of resulting bytes, excluding the trailing NUL. */ return length;