top: Check width and col.

Otherwise they may lead to out-of-bounds writes (snprintf() returns the
number of characters which would have been written if enough space had
been available).

Also, make sure buf is null-terminated after COLPLUSCH has been written.
This commit is contained in:
Qualys Security Advisory 1970-01-01 00:00:00 +00:00 committed by Craig Small
parent 97a989cbcd
commit bbe58d7e0a

View File

@ -203,7 +203,7 @@ static int *PHash_sav = HHash_one, // alternating 'old/new' hash tables
static int Autox_array [EU_MAXPFLGS], static int Autox_array [EU_MAXPFLGS],
Autox_found; Autox_found;
#define AUTOX_NO EU_MAXPFLGS #define AUTOX_NO EU_MAXPFLGS
#define AUTOX_COL(f) if (EU_MAXPFLGS > f) Autox_array[f] = Autox_found = 1 #define AUTOX_COL(f) if (EU_MAXPFLGS > f && f >= 0) Autox_array[f] = Autox_found = 1
#define AUTOX_MODE (0 > Rc.fixed_widest) #define AUTOX_MODE (0 > Rc.fixed_widest)
/* Support for scale_mem and scale_num (to avoid duplication. */ /* Support for scale_mem and scale_num (to avoid duplication. */
@ -1643,7 +1643,10 @@ static inline const char *make_num (long num, int width, int justr, int col, int
goto end_justifies; goto end_justifies;
if (width < snprintf(buf, sizeof(buf), "%ld", num)) { if (width < snprintf(buf, sizeof(buf), "%ld", num)) {
if (width <= 0 || (size_t)width >= sizeof(buf))
width = sizeof(buf)-1;
buf[width-1] = COLPLUSCH; buf[width-1] = COLPLUSCH;
buf[width] = '\0';
AUTOX_COL(col); AUTOX_COL(col);
} }
end_justifies: end_justifies:
@ -1658,7 +1661,10 @@ static inline const char *make_str (const char *str, int width, int justr, int c
static char buf[SCREENMAX]; static char buf[SCREENMAX];
if (width < snprintf(buf, sizeof(buf), "%s", str)) { if (width < snprintf(buf, sizeof(buf), "%s", str)) {
if (width <= 0 || (size_t)width >= sizeof(buf))
width = sizeof(buf)-1;
buf[width-1] = COLPLUSCH; buf[width-1] = COLPLUSCH;
buf[width] = '\0';
AUTOX_COL(col); AUTOX_COL(col);
} }
return justify_pad(buf, width, justr); return justify_pad(buf, width, justr);