From d02b7bd864706fc2a40d83fb6014772ad3cc3b80 Mon Sep 17 00:00:00 2001 From: nobu Date: Wed, 28 Mar 2018 10:12:17 +0000 Subject: pack.c: fix underflow * pack.c (pack_unpack_internal): get rid of underflow. https://hackerone.com/reports/298246 git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/trunk@62992 b2dd03c8-39d4-4d8f-98ff-823fe69b080e --- pack.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'pack.c') diff --git a/pack.c b/pack.c index 3f2955e4cc..3413ec6c56 100644 --- a/pack.c +++ b/pack.c @@ -1128,7 +1128,7 @@ pack_unpack_internal(VALUE str, VALUE fmt, int mode) else if (ISDIGIT(*p)) { errno = 0; len = STRTOUL(p, (char**)&p, 10); - if (errno) { + if (len < 0 || errno) { rb_raise(rb_eRangeError, "pack length too big"); } } -- cgit v1.2.3