diff options
author | Yusuke Endoh <mame@ruby-lang.org> | 2019-07-15 06:42:55 +0900 |
---|---|---|
committer | Yusuke Endoh <mame@ruby-lang.org> | 2019-07-15 06:44:16 +0900 |
commit | d37da601289d13396b1e986b81d51b05bcfdddd5 (patch) | |
tree | 2ca922b27dad3f4f87a0f23486dab71e1a35155b /time.c | |
parent | ea711285737faac6471fc22f0b8f9e9365e7e6ed (diff) | |
download | ruby-d37da601289d13396b1e986b81d51b05bcfdddd5.tar.gz |
time.c (time_mdump): use another buffer for year_extend
ruby_marshal_write_long may write 9 bytes, but buf has only 8 bytes.
So the buffer cannot be reused. This issue was found by Coverity Scan.
Diffstat (limited to 'time.c')
-rw-r--r-- | time.c | 6 |
1 files changed, 3 insertions, 3 deletions
@@ -5090,15 +5090,15 @@ time_mdump(VALUE time) * binary (like as Fixnum and Bignum). */ size_t ysize = rb_absint_size(year_extend, NULL); - char *p; + char *p, buf_year_extend[9]; if (ysize > LONG_MAX || - (i = ruby_marshal_write_long((long)ysize, buf)) < 0) { + (i = ruby_marshal_write_long((long)ysize, buf_year_extend)) < 0) { rb_raise(rb_eArgError, "year too %s to marshal: %"PRIsVALUE" UTC", (year == 1900 ? "small" : "big"), vtm.year); } rb_str_resize(str, sizeof(buf) + i + ysize); p = RSTRING_PTR(str) + sizeof(buf); - memcpy(p, buf, i); + memcpy(p, buf_year_extend, i); p += i; rb_integer_pack(year_extend, p, ysize, 1, 0, INTEGER_PACK_LITTLE_ENDIAN); } |