summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorakr <akr@b2dd03c8-39d4-4d8f-98ff-823fe69b080e>2009-02-21 17:04:22 +0000
committerakr <akr@b2dd03c8-39d4-4d8f-98ff-823fe69b080e>2009-02-21 17:04:22 +0000
commit67ac3f7c529a47d36ec8fa1f4417d2042d0b23f7 (patch)
treeebbf951ad949fc526bb53e1b4df9a1eac57db9cd
parentd7d5fe8359348d08a301c67fc9b2a37dd105832b (diff)
downloadruby-67ac3f7c529a47d36ec8fa1f4417d2042d0b23f7.tar.gz
ruby-67ac3f7c529a47d36ec8fa1f4417d2042d0b23f7.tar.xz
ruby-67ac3f7c529a47d36ec8fa1f4417d2042d0b23f7.zip
* ext/socket/ancdata.c (bsock_recvmsg_internal): check max length
overflow. git-svn-id: http://svn.ruby-lang.org/repos/ruby/trunk@22491 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
-rw-r--r--ChangeLog5
-rw-r--r--ext/socket/ancdata.c6
2 files changed, 11 insertions, 0 deletions
diff --git a/ChangeLog b/ChangeLog
index 259c60427..138f1e0fe 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,8 @@
+Sun Feb 22 02:03:46 2009 Tanaka Akira <akr@fsij.org>
+
+ * ext/socket/ancdata.c (bsock_recvmsg_internal): check max length
+ overflow.
+
Sun Feb 22 01:52:30 2009 Tanaka Akira <akr@fsij.org>
* ext/socket/ancdata.c (bsock_recvmsg_internal): don't call
diff --git a/ext/socket/ancdata.c b/ext/socket/ancdata.c
index 28f00649d..e3f56fe50 100644
--- a/ext/socket/ancdata.c
+++ b/ext/socket/ancdata.c
@@ -1313,6 +1313,8 @@ bsock_recvmsg_internal(int argc, VALUE *argv, VALUE sock, int nonblock)
int grown = 0;
#if defined(HAVE_ST_MSG_CONTROL)
if (NIL_P(vmaxdatlen) && (mh.msg_flags & MSG_TRUNC)) {
+ if (SIZE_MAX/2 < maxdatlen)
+ rb_raise(rb_eArgError, "max data length too big");
maxdatlen *= 2;
grown = 1;
}
@@ -1328,6 +1330,8 @@ bsock_recvmsg_internal(int argc, VALUE *argv, VALUE sock, int nonblock)
}
}
else {
+ if (SIZE_MAX/2 < maxctllen)
+ rb_raise(rb_eArgError, "max control message length too big");
maxctllen *= 2;
grown = 1;
}
@@ -1335,6 +1339,8 @@ bsock_recvmsg_internal(int argc, VALUE *argv, VALUE sock, int nonblock)
}
#else
if (NIL_P(vmaxdatlen) && ss != -1 && ss == iov.iov_len) {
+ if (SIZE_MAX/2 < maxdatlen)
+ rb_raise(rb_eArgError, "max data length too big");
maxdatlen *= 2;
grown = 1;
}