diff options
author | Darren Tucker <dtucker@cvs.openbsd.org> | 2016-10-14 18:19:05 +0000 |
---|---|---|
committer | Darren Tucker <dtucker@cvs.openbsd.org> | 2016-10-14 18:19:05 +0000 |
commit | a04f61a84dc029b00830c6249970fdfac246f2c5 (patch) | |
tree | f856e5245f83e63256ebb952e7e824ba0b48a145 /lib/libc/string/strlcat.c | |
parent | 222aa69ded140125385a20105b8805de09c47438 (diff) |
Cast pointers to uintptr_t to avoid potential signedness errors.
Based on patch from yuanjie.huang at windriver.com via OpenSSH bz#2608,
with & ok millert, ok deraadt.
Diffstat (limited to 'lib/libc/string/strlcat.c')
-rw-r--r-- | lib/libc/string/strlcat.c | 12 |
1 files changed, 9 insertions, 3 deletions
diff --git a/lib/libc/string/strlcat.c b/lib/libc/string/strlcat.c index 073b0d42594..410f448b56a 100644 --- a/lib/libc/string/strlcat.c +++ b/lib/libc/string/strlcat.c @@ -1,4 +1,4 @@ -/* $OpenBSD: strlcat.c,v 1.16 2015/08/31 02:53:57 guenther Exp $ */ +/* $OpenBSD: strlcat.c,v 1.17 2016/10/14 18:19:04 dtucker Exp $ */ /* * Copyright (c) 1998, 2015 Todd C. Miller <Todd.Miller@courtesan.com> @@ -18,6 +18,7 @@ #include <sys/types.h> #include <string.h> +#include <stdint.h> /* * Appends src to string dst of size dsize (unlike strncat, dsize is the @@ -37,7 +38,7 @@ strlcat(char *dst, const char *src, size_t dsize) /* Find the end of dst and adjust bytes left but don't go past end. */ while (n-- != 0 && *dst != '\0') dst++; - dlen = dst - odst; + dlen = (uintptr_t)dst - (uintptr_t)odst; n = dsize - dlen; if (n-- == 0) @@ -51,6 +52,11 @@ strlcat(char *dst, const char *src, size_t dsize) } *dst = '\0'; - return(dlen + (src - osrc)); /* count does not include NUL */ + /* + * Cast pointers to unsigned type before calculation, to avoid signed + * overflow when the string ends where the MSB has changed. + * Return value does not include NUL. + */ + return (dlen + ((uintptr_t)src - (uintptr_t)osrc)); } DEF_WEAK(strlcat); |