Skip to content

Commit

Permalink
Fix buffer overflow in config parser
Browse files Browse the repository at this point in the history
When interpreting a config value, the config parser reads in 1+ space
character(s) and puts -one- space character in the buffer as soon as
the first non-space character is encountered (if not inside quotes).

Unfortunately the buffer size check lacks the extra space character
which gets inserted at the next non-space character, resulting in
a crash with a specially crafted config entry.

The unit test now uses Java to compile a platform independent
.NET framework to output the test string in C# :o)

    Read: Thanks to Johannes Sixt for the correct printf call
    which replaces the perl invocation.

Signed-off-by: Thomas Jarosch <thomas.jarosch@intra2net.com>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
  • Loading branch information
Thomas Jarosch authored and Junio C Hamano committed Apr 18, 2009
1 parent c6d8f76 commit e0b3cc0
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 2 deletions.
2 changes: 1 addition & 1 deletion config.c
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ static char *parse_value(void)

for (;;) {
int c = get_next_char();
if (len >= sizeof(value))
if (len >= sizeof(value) - 1)
return NULL;
if (c == '\n') {
if (quote)
Expand Down
9 changes: 8 additions & 1 deletion t/t1303-wacky-config.sh
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ setup() {

check() {
echo "$2" >expected
git config --get "$1" >actual
git config --get "$1" >actual 2>&1
test_cmp actual expected
}

Expand Down Expand Up @@ -40,4 +40,11 @@ test_expect_success 'make sure git config escapes section names properly' '
check "$SECTION" bar
'

LONG_VALUE=$(printf "x%01021dx a" 7)
test_expect_success 'do not crash on special long config line' '
setup &&
git config section.key "$LONG_VALUE" &&
check section.key "fatal: bad config file line 2 in .git/config"
'

test_done

0 comments on commit e0b3cc0

Please sign in to comment.