summaryrefslogtreecommitdiff
path: root/changes/memarea_overflow
AgeCommit message (Collapse)Author
2016-05-25Fix a pointer arithmetic bug in memarea_alloc()Nick Mathewson
Fortunately, the arithmetic cannot actually overflow, so long as we *always* check for the size of potentially hostile input before copying it. I think we do, though. We do check each line against MAX_LINE_LENGTH, and each object name or object against MAX_UNPARSED_OBJECT_SIZE, both of which are 128k. So to get this overflow, we need to have our memarea allocated way way too high up in RAM, which most allocators won't actually do. Bugfix on 0.2.1.1-alpha, where memarea was introduced. Found by Guido Vranken.