Skip to content

Commit b2e55ed

Browse files
committed
patch 9.2.0278: viminfo: heap buffer overflow when reading viminfo file
Problem: Reading a crafted viminfo file can cause a heap buffer overflow because the length value from getdigits() is cast to int, truncating large size_t values Solution: Remove the (int) cast when calling alloc() (sentinel404) Signed-off-by: Christian Brabandt <cb@256bit.org>
1 parent 3e60f03 commit b2e55ed

3 files changed

Lines changed: 23 additions & 1 deletion

File tree

src/testdir/test_viminfo.vim

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1371,4 +1371,24 @@ func Test_viminfo_len_one()
13711371
let &viminfofile = _viminfofile
13721372
endfunc
13731373

1374+
func Test_viminfo_len_overflow()
1375+
let _viminfofile = &viminfofile
1376+
let &viminfofile=''
1377+
let viminfo_file = tempname()
1378+
defer delete(viminfo_file)
1379+
1380+
" Craft a viminfo entry with size_t length overflow
1381+
call writefile(['# Viminfo',
1382+
\ '|1,4', '|2,>4294967311',
1383+
\ '|<"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA',
1384+
\ '|<BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB',
1385+
\ '|<CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC',
1386+
\ '|<DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD'], viminfo_file, 'b')
1387+
1388+
" Should not crash or cause memory errors
1389+
exe 'rviminfo! ' .. viminfo_file
1390+
1391+
let &viminfofile = _viminfofile
1392+
endfunc
1393+
13741394
" vim: shiftwidth=2 sts=2 expandtab

src/version.c

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -734,6 +734,8 @@ static char *(features[]) =
734734

735735
static int included_patches[] =
736736
{ /* Add new patch number below this line */
737+
/**/
738+
278,
737739
/**/
738740
277,
739741
/**/

src/viminfo.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1054,7 +1054,7 @@ barline_parse(vir_T *virp, char_u *text, garray_T *values)
10541054
// Length includes the quotes.
10551055
++p;
10561056
len = getdigits(&p);
1057-
buf = alloc((int)(len + 1));
1057+
buf = alloc(len + 1);
10581058
if (buf == NULL)
10591059
return TRUE;
10601060
p = buf;

0 commit comments

Comments
 (0)