Files
tor/src/common
Tobias Stoeckmann 0d4a689d3a Prevent UB on signed overflow.
Overflowing a signed integer in C is an undefined behaviour.
It is possible to trigger this undefined behaviour in tor_asprintf on
Windows or systems lacking vasprintf.

On these systems, eiter _vscprintf or vsnprintf is called to retrieve
the required amount of bytes to hold the string. These functions can
return INT_MAX. The easiest way to recreate this is the use of a
specially crafted configuration file, e.g. containing the line:

FirewallPorts AAAAA<in total 2147483610 As>

This line triggers the needed tor_asprintf call which eventually
leads to an INT_MAX return value from _vscprintf or vsnprintf.

The needed byte for \0 is added to the result, triggering the
overflow and therefore the undefined behaviour.

Casting the value to size_t before addition fixes the behaviour.

Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2019-07-19 09:17:25 -04:00
..
2018-11-12 15:39:28 -05:00
2016-02-27 18:48:19 +01:00
2016-02-27 18:48:19 +01:00
2016-02-27 18:48:19 +01:00
2019-07-19 09:17:25 -04:00
2016-10-17 10:25:13 -04:00
2016-02-27 18:48:19 +01:00
2016-05-25 10:21:15 -04:00
2016-02-27 18:48:19 +01:00
2016-09-16 11:21:33 -04:00
2016-06-09 11:50:25 +00:00
2016-06-09 11:50:25 +00:00
2016-05-25 09:27:47 -04:00
2016-02-27 18:48:19 +01:00
2016-02-27 18:48:19 +01:00
2016-05-12 09:56:42 -04:00
2016-06-09 11:50:25 +00:00
2016-07-29 05:05:12 +00:00
2016-02-27 18:48:19 +01:00
2016-02-27 18:48:19 +01:00
2018-10-15 12:47:19 -04:00
2016-02-27 18:48:19 +01:00
2016-07-05 12:10:12 -04:00