Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley

Ansariel 2014-08-26 21:49:50 +02:00
parent 9a679a27ac
commit 7d92321c3c
1 changed files with 16 additions and 4 deletions

View File

@ -1566,22 +1566,34 @@ const char *LLXMLNode::parseFloat(const char *str, F64 *dest, U32 precision, Enc
{
str = skipWhitespace(str);
if (memcmp(str, "inf", 3) == 0)
// <FS> Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley
//if (memcmp(str, "inf", 3) == 0)
if (strncmp(str, "inf", 3) == 0)
// </FS>
{
*(U64 *)dest = 0x7FF0000000000000ll;
return str + 3;
}
if (memcmp(str, "-inf", 4) == 0)
// <FS> Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley
//if (memcmp(str, "-inf", 4) == 0)
if (strncmp(str, "-inf", 4) == 0)
// </FS>
{
*(U64 *)dest = 0xFFF0000000000000ll;
return str + 4;
}
if (memcmp(str, "1.#INF", 6) == 0)
// <FS> Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley
//if (memcmp(str, "1.#INF", 6) == 0)
if (strncmp(str, "1.#INF", 6) == 0)
// </FS>
{
*(U64 *)dest = 0x7FF0000000000000ll;
return str + 6;
}
if (memcmp(str, "-1.#INF", 7) == 0)
// <FS> Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley
//if (memcmp(str, "-1.#INF", 7) == 0)
if (strncmp(str, "-1.#INF", 7) == 0)
// </FS>
{
*(U64 *)dest = 0xFFF0000000000000ll;
return str + 7;