Browse Source

fix some length calculations in memory streams

rs-1.0
Rich Felker 15 years ago
parent
commit
1e69376435
  1. 2
      src/stdio/open_memstream.c
  2. 4
      src/stdio/open_wmemstream.c

2
src/stdio/open_memstream.c

@ -41,7 +41,7 @@ static size_t ms_write(FILE *f, const unsigned char *buf, size_t len)
f->wpos = f->wbase;
if (ms_write(f, f->wbase, len2) < len2) return 0;
}
if (len > c->space - c->pos) {
if (len >= c->space - c->pos) {
len2 = 2*c->space+1 | c->space+len+1;
newbuf = realloc(c->buf, len2);
if (!newbuf) return 0;

4
src/stdio/open_wmemstream.c

@ -39,13 +39,13 @@ static size_t wms_write(FILE *f, const unsigned char *buf, size_t len)
struct cookie *c = f->cookie;
size_t len2;
wchar_t *newbuf;
if (len > c->space - c->pos) {
if (len >= c->space - c->pos) {
len2 = 2*c->space+1 | c->space+len+1;
if (len2 > SSIZE_MAX/4) return 0;
newbuf = realloc(c->buf, len2*4);
if (!newbuf) return 0;
*c->bufp = c->buf = newbuf;
memset(c->buf + c->space, 0, len2 - c->space);
memset(c->buf + c->space, 0, 4*(len2 - c->space));
c->space = len2;
}

Loading…
Cancel
Save