gbranden pushed a commit to branch master
in repository groff.

commit cca6188a818375d42b450cb2877d61e289047fd5
Author: G. Branden Robinson <[email protected]>
AuthorDate: Tue Sep 29 00:25:00 2026 -0500

    [hpftodit]: Fix Savannah #68680.
    
    * src/utils/hpftodit/hpftodit.cpp (hp_msl_to_ucode_name)
      (unicode_to_ucode_name): Prevent heap buffer overwrite by adequately
      sizing buffer for the `u` character we prefix to a Unicode code point
      identifier if the character is not unnamed.
    
    Fixes <https://savannah.gnu.org/bugs/?68680>.  Thanks to Pavol Sloboda
    for the report and a reproducer.  Problem appears to date back to commit
    65a386ebce, 2003-12-27.
---
 ChangeLog                       | 11 +++++++++++
 src/utils/hpftodit/hpftodit.cpp | 17 +++++++++++++----
 2 files changed, 24 insertions(+), 4 deletions(-)

diff --git a/ChangeLog b/ChangeLog
index 1c24bea5d..ce4503dc6 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,14 @@
+2026-09-29  G. Branden Robinson <[email protected]>
+
+       * src/utils/hpftodit/hpftodit.cpp (hp_msl_to_ucode_name)
+       (unicode_to_ucode_name): Prevent heap buffer overwrite by
+       adequately sizing buffer for the `u` character we prefix to a
+       Unicode code point identifier if the character is not unnamed.
+
+       Fixes <https://savannah.gnu.org/bugs/?68680>.  Thanks to Pavol
+       Sloboda for the report and a reproducer.  Problem appears to
+       date back to commit 65a386ebce, 2003-12-27.
+
 2026-09-29  G. Branden Robinson <[email protected]>
 
        [hpftodit]: Regression-test Savannah #68680.
diff --git a/src/utils/hpftodit/hpftodit.cpp b/src/utils/hpftodit/hpftodit.cpp
index 950e58f91..722857374 100644
--- a/src/utils/hpftodit/hpftodit.cpp
+++ b/src/utils/hpftodit/hpftodit.cpp
@@ -54,6 +54,7 @@ put filename in error messages (or fix lib)
 
 extern "C" const char *Version_string;
 
+// TODO: Migrate to C2y's streq().
 #define equal(a, b) (strcmp(a, b) == 0)
 // only valid if is_uname(c) has returned true
 #define is_decomposed(c) strchr(c, '_')
@@ -1317,8 +1318,12 @@ hp_msl_to_ucode_name(int msl)
       // 1st char is the number of components
       ustr = uname_decomposed + 1;
   }
-  char *value = new char[strlen(ustr) + 1];
-  sprintf(value, equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
+  size_t valuelen = strlen(ustr) + 1 /* possible 'u' */ + 1 /* '\0' */;
+  // C++03: new char[valuelen]();
+  char *value = new char[valuelen];
+  (void) memset(value, 0, valuelen);
+  (void) snprintf(value, valuelen,
+                 equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
   return value;
 }
 
@@ -1343,8 +1348,12 @@ unicode_to_ucode_name(int ucode)
       // 1st char is the number of components
       ustr = uname_decomposed + 1;
   }
-  char *value = new char[strlen(ustr) + 1];
-  sprintf(value, equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
+  size_t valuelen = strlen(ustr) + 1 /* possible 'u' */ + 1 /* '\0' */;
+  // C++03: new char[valuelen]();
+  char *value = new char[valuelen];
+  (void) memset(value, 0, valuelen);
+  (void) snprintf(value, valuelen,
+                 equal(ustr, UNNAMED) ? UNNAMED : "u%s", ustr);
   return value;
 }
 

_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit

Reply via email to