2024-09-27 09:07:54 +02:00
|
|
|
From c55dcbb77bb0bd7e61ce5c7a074013be06b32629 Mon Sep 17 00:00:00 2001
|
2024-04-03 01:15:00 +02:00
|
|
|
From: Valery Ushakov <uwe@stderr.spb.ru>
|
|
|
|
Date: Wed, 24 Jan 2024 22:24:41 +0300
|
|
|
|
Subject: [PATCH] awk.c: fix CVE-2023-42366 (bug #15874)
|
|
|
|
|
|
|
|
Make sure we don't read past the end of the string in next_token()
|
|
|
|
when backslash is the last character in an (invalid) regexp.
|
|
|
|
|
|
|
|
https://bugs.busybox.net/show_bug.cgi?id=15874
|
|
|
|
---
|
|
|
|
editors/awk.c | 6 ++++--
|
|
|
|
1 file changed, 4 insertions(+), 2 deletions(-)
|
|
|
|
|
|
|
|
diff --git a/editors/awk.c b/editors/awk.c
|
2024-09-27 09:07:54 +02:00
|
|
|
index 64e752f4b..222e6298d 100644
|
2024-04-03 01:15:00 +02:00
|
|
|
--- a/editors/awk.c
|
|
|
|
+++ b/editors/awk.c
|
2024-09-27 09:07:54 +02:00
|
|
|
@@ -1234,9 +1234,11 @@ static uint32_t next_token(uint32_t expected)
|
2024-04-03 01:15:00 +02:00
|
|
|
s[-1] = bb_process_escape_sequence((const char **)&pp);
|
|
|
|
if (*p == '\\')
|
|
|
|
*s++ = '\\';
|
|
|
|
- if (pp == p)
|
|
|
|
+ if (pp == p) {
|
|
|
|
+ if (*p == '\0')
|
|
|
|
+ syntax_error(EMSG_UNEXP_EOS);
|
|
|
|
*s++ = *p++;
|
|
|
|
- else
|
|
|
|
+ } else
|
|
|
|
p = pp;
|
|
|
|
}
|
|
|
|
}
|