Skip to content

Commit

Permalink
Fix buffer overflow in prepare_attr_stack
Browse files Browse the repository at this point in the history
If PATH_MAX on your system is smaller than a path stored in the git repo,
it may cause the buffer overflow in prepare_attr_stack.

Signed-off-by: Dmitry Potapov <dpotapov@gmail.com>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
  • Loading branch information
Dmitry Potapov authored and Junio C Hamano committed Jul 16, 2008
1 parent fd55a19 commit f66cf96
Showing 1 changed file with 9 additions and 6 deletions.
15 changes: 9 additions & 6 deletions attr.c
Original file line number Diff line number Diff line change
Expand Up @@ -459,7 +459,9 @@ static void prepare_attr_stack(const char *path, int dirlen)
{
struct attr_stack *elem, *info;
int len;
char pathbuf[PATH_MAX];
struct strbuf pathbuf;

strbuf_init(&pathbuf, dirlen+2+strlen(GITATTRIBUTES_FILE));

/*
* At the bottom of the attribute stack is the built-in
Expand Down Expand Up @@ -510,13 +512,14 @@ static void prepare_attr_stack(const char *path, int dirlen)
len = strlen(attr_stack->origin);
if (dirlen <= len)
break;
memcpy(pathbuf, path, dirlen);
memcpy(pathbuf + dirlen, "/", 2);
cp = strchr(pathbuf + len + 1, '/');
strbuf_reset(&pathbuf);
strbuf_add(&pathbuf, path, dirlen);
strbuf_addch(&pathbuf, '/');
cp = strchr(pathbuf.buf + len + 1, '/');
strcpy(cp + 1, GITATTRIBUTES_FILE);
elem = read_attr(pathbuf, 0);
elem = read_attr(pathbuf.buf, 0);
*cp = '\0';
elem->origin = strdup(pathbuf);
elem->origin = strdup(pathbuf.buf);
elem->prev = attr_stack;
attr_stack = elem;
debug_push(elem);
Expand Down

0 comments on commit f66cf96

Please sign in to comment.