public inbox for gcc-prs@sourceware.org help / color / mirror / Atom feed
From: peturr02@ru.is To: gcc-gnats@gcc.gnu.org Subject: libstdc++/9538: Out-of-bounds memory access in streambuf::sputbackc Date: Sun, 02 Feb 2003 11:56:00 -0000 [thread overview] Message-ID: <20030202114744.2547.qmail@sources.redhat.com> (raw) >Number: 9538 >Category: libstdc++ >Synopsis: Out-of-bounds memory access in streambuf::sputbackc >Confidential: no >Severity: serious >Priority: medium >Responsible: unassigned >State: open >Class: sw-bug >Submitter-Id: net >Arrival-Date: Sun Feb 02 11:56:00 UTC 2003 >Closed-Date: >Last-Modified: >Originator: peturr02@ru.is >Release: gcc-3.2.1 >Organization: >Environment: Red Hat Linux 8.0 >Description: basic_streambuf<>::sputbackc accesses gptr()[-1] without first checking if gptr() > eback(). This can be a fatal error if (gptr() - 1) is not a valid address or if char_type is a class type. >How-To-Repeat: See attachment. >Fix: >Release-Note: >Audit-Trail: >Unformatted: ----gnatsweb-attachment---- Content-Type: text/plain; name="sputbackcbug2.cc" Content-Disposition: inline; filename="sputbackcbug2.cc" #include <streambuf> #undef NDEBUG #include <cassert> using namespace std; class MyTraits : public char_traits<char> { public: static bool eq(char c1, char c2) { assert(c1 >= 0); assert(c2 >= 0); return char_traits<char>::eq(c1, c2); } }; class MyBuf : public basic_streambuf<char, MyTraits> { char buffer[8]; public: MyBuf() { memset(buffer, -1, sizeof(buffer)); memset(buffer + 2, 0, 4); setg(buffer + 2, buffer + 2, buffer + 6); } }; int main() { MyBuf mb; mb.sputbackc(0); return 0; }
next reply other threads:[~2003-02-02 11:56 UTC|newest] Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top 2003-02-02 11:56 peturr02 [this message] 2003-02-02 18:48 paolo 2003-02-04 18:19 paolo
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20030202114744.2547.qmail@sources.redhat.com \ --to=peturr02@ru.is \ --cc=gcc-gnats@gcc.gnu.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).