gbranden pushed a commit to branch master
in repository groff.
commit cca6188a818375d42b450cb2877d61e289047fd5
Author: G. Branden Robinson <[email protected]>
AuthorDate: Tue Sep 29 00:25:00 2026 -0500
[hpftodit]: Fix Savannah #68680.
* src/utils/hpftodit/hpftodit.cpp (hp_msl_to_ucode_name)
(unicode_to_ucode_name): Prevent heap buffer overwrite by adequately
sizing buffer for the `u` character we prefix to a Unicode code point
identifier if the character is not unnamed.
Fixes <https://savannah.gnu.org/bugs/?68680>. Thanks to Pavol Sloboda
for the report and a reproducer. Problem appears to date back to commit
65a386ebce, 2003-12-27.
---
ChangeLog | 11 +++++++++++
src/utils/hpftodit/hpftodit.cpp | 17 +++++++++++++----
2 files changed, 24 insertions(+), 4 deletions(-)
diff --git a/ChangeLog b/ChangeLog
index 1c24bea5d..ce4503dc6 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,14 @@
+2026-09-29 G. Branden Robinson <[email protected]>
+
+ * src/utils/hpftodit/hpftodit.cpp (hp_msl_to_ucode_name)
+ (unicode_to_ucode_name): Prevent heap buffer overwrite by
+ adequately sizing buffer for the `u` character we prefix to a
+ Unicode code point identifier if the character is not unnamed.
+
+ Fixes <https://savannah.gnu.org/bugs/?68680>. Thanks to Pavol
+ Sloboda for the report and a reproducer. Problem appears to
+ date back to commit 65a386ebce, 2003-12-27.
+
2026-09-29 G. Branden Robinson <[email protected]>
[hpftodit]: Regression-test Savannah #68680.
diff --git a/src/utils/hpftodit/hpftodit.cpp b/src/utils/hpftodit/hpftodit.cpp
index 950e58f91..722857374 100644
--- a/src/utils/hpftodit/hpftodit.cpp
+++ b/src/utils/hpftodit/hpftodit.cpp
@@ -54,6 +54,7 @@ put filename in error messages (or fix lib)
extern "C" const char *Version_string;
+// TODO: Migrate to C2y's streq().
#define equal(a, b) (strcmp(a, b) == 0)
// only valid if is_uname(c) has returned true
#define is_decomposed(c) strchr(c, '_')
@@ -1317,8 +1318,12 @@ hp_msl_to_ucode_name(int msl)
// 1st char is the number of components
ustr = uname_decomposed + 1;
}
- char *value = new char[strlen(ustr) + 1];
- sprintf(value, equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
+ size_t valuelen = strlen(ustr) + 1 /* possible 'u' */ + 1 /* '\0' */;
+ // C++03: new char[valuelen]();
+ char *value = new char[valuelen];
+ (void) memset(value, 0, valuelen);
+ (void) snprintf(value, valuelen,
+ equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
return value;
}
@@ -1343,8 +1348,12 @@ unicode_to_ucode_name(int ucode)
// 1st char is the number of components
ustr = uname_decomposed + 1;
}
- char *value = new char[strlen(ustr) + 1];
- sprintf(value, equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
+ size_t valuelen = strlen(ustr) + 1 /* possible 'u' */ + 1 /* '\0' */;
+ // C++03: new char[valuelen]();
+ char *value = new char[valuelen];
+ (void) memset(value, 0, valuelen);
+ (void) snprintf(value, valuelen,
+ equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
return value;
}
_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit