Browse Source

dc: Parse error & fix out of bounds read in xc_program_printString

function                                             old     new   delta
xc_program_print                                     712     735     +23

Signed-off-by: Brian Foley <bpfoley@google.com>
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
Brian Foley 4 years ago
parent
commit
10509a70ee
2 changed files with 24 additions and 2 deletions
  1. 4 2
      miscutils/bc.c
  2. 20 0
      testsuite/dc.tests

+ 4 - 2
miscutils/bc.c

@@ -5456,11 +5456,13 @@ static void xc_program_printString(const char *str)
 			char *n;
 
 			c = *str++;
-			n = strchr(esc, c); // note: c can be NUL
-			if (!n) {
+			n = strchr(esc, c); // note: if c is NUL, n = \0 at end of esc
+			if (!n || !c) {
 				// Just print the backslash and following character
 				bb_putchar('\\');
 				++G.prog.nchars;
+				// But if we're at the end of the string, stop
+				if (!c) break;
 			} else {
 				if (n - esc == 0) // "\n" ?
 					G.prog.nchars = SIZE_MAX;

+ 20 - 0
testsuite/dc.tests

@@ -59,6 +59,26 @@ testing "dc: x should work with strings created from a" \
 	"42\n" \
 	"" ""
 
+testing "dc: p should print invalid escapes" \
+	"dc -e '[\q] p'" \
+	"\\q\n" \
+	"" ""
+
+testing "dc: p should print trailing backslashes" \
+	"dc -e '[q\] p'" \
+	"q\\\\\n" \
+	"" ""
+
+testing "dc: p should parse/print single backslashes" \
+	"dc -e '[\] p'" \
+	"\\\\\n" \
+	"" ""
+
+testing "dc: p should print single backslash strings" \
+	"dc -e '92 a p'" \
+	"\\\\\n" \
+	"" ""
+
 testing "dc read" \
 	"dc -finput" \
 	"2\n9\n1\n" \