diff options
author | nobu <nobu@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2011-01-24 23:28:22 +0000 |
---|---|---|
committer | nobu <nobu@b2dd03c8-39d4-4d8f-98ff-823fe69b080e> | 2011-01-24 23:28:22 +0000 |
commit | ced2d699b05ae5557f075ab6c0fa8111a7526b6e (patch) | |
tree | ef2ee7ed23f238b6d28a8e597365b0aa5e184f7e | |
parent | 9a4a8673c08b1980d8bf4f9a1154bc1175c77b2b (diff) | |
download | ruby-ced2d699b05ae5557f075ab6c0fa8111a7526b6e.tar.gz |
* string.c (rb_str_resize): get rid of out-of-bound access.
git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/trunk@30652 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
-rw-r--r-- | ChangeLog | 4 | ||||
-rw-r--r-- | string.c | 3 |
2 files changed, 6 insertions, 1 deletions
@@ -1,3 +1,7 @@ +Tue Jan 25 08:28:19 2011 Nobuyoshi Nakada <nobu@ruby-lang.org> + + * string.c (rb_str_resize): get rid of out-of-bound access. + Tue Jan 25 07:48:22 2011 Kazuhiro NISHIYAMA <zn@mbf.nifty.com> * test/ruby/test_thread.rb: remove unused variables. @@ -1748,7 +1748,8 @@ rb_str_resize(VALUE str, long len) else if (len <= RSTRING_EMBED_LEN_MAX) { char *ptr = RSTRING(str)->as.heap.ptr; STR_SET_EMBED(str); - if (slen > 0) MEMCPY(RSTRING(str)->as.ary, ptr, char, len); + if (slen > len) slen = len; + if (slen > 0) MEMCPY(RSTRING(str)->as.ary, ptr, char, slen); RSTRING(str)->as.ary[len] = '\0'; STR_SET_EMBED_LEN(str, len); if (independent) xfree(ptr); |