Skip to content
This repository has been archived by the owner on Jan 23, 2025. It is now read-only.

Commit

Permalink
Merge pull request #1 from niooss-ledger/backport_verify_stream_size_…
Browse files Browse the repository at this point in the history
…to_0.3.9.3

Backport "Verify stream size before allocating string / bytes."
  • Loading branch information
pandouard authored Nov 24, 2020
2 parents c4d8b9a + 06cc18e commit 8e24ca7
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions pb_decode.c
Original file line number Diff line number Diff line change
Expand Up @@ -1431,6 +1431,9 @@ static bool checkreturn pb_dec_bytes(pb_istream_t *stream, const pb_field_t *fie
#ifndef PB_ENABLE_MALLOC
PB_RETURN_ERROR(stream, "no malloc support");
#else
if (stream->bytes_left < size)
PB_RETURN_ERROR(stream, "end-of-stream");

#ifdef PB_ENABLE_ADV_SIZE_CHECK
/* field.max_size_limit == 0 disables pre-mem alloc check */
if (field->max_size_limit > 0 && alloc_size > field->max_size_limit){
Expand Down Expand Up @@ -1473,6 +1476,9 @@ static bool checkreturn pb_dec_string(pb_istream_t *stream, const pb_field_t *fi
#ifndef PB_ENABLE_MALLOC
PB_RETURN_ERROR(stream, "no malloc support");
#else
if (stream->bytes_left < size)
PB_RETURN_ERROR(stream, "end-of-stream");

# ifdef PB_ENABLE_ADV_SIZE_CHECK
/* field.max_size_limit == 0 disables pre- mem alloc check */
if (field->max_size_limit > 0 && alloc_size > field->max_size_limit){
Expand Down

0 comments on commit 8e24ca7

Please sign in to comment.