From 7d92321c3c28febff5d2937627e02f3ee65e075d Mon Sep 17 00:00:00 2001 From: Ansariel Date: Tue, 26 Aug 2014 21:49:50 +0200 Subject: [PATCH] Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley --- indra/llxml/llxmlnode.cpp | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/indra/llxml/llxmlnode.cpp b/indra/llxml/llxmlnode.cpp index 9028d2faf5..6637421d37 100755 --- a/indra/llxml/llxmlnode.cpp +++ b/indra/llxml/llxmlnode.cpp @@ -1566,22 +1566,34 @@ const char *LLXMLNode::parseFloat(const char *str, F64 *dest, U32 precision, Enc { str = skipWhitespace(str); - if (memcmp(str, "inf", 3) == 0) + // Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley + //if (memcmp(str, "inf", 3) == 0) + if (strncmp(str, "inf", 3) == 0) + // { *(U64 *)dest = 0x7FF0000000000000ll; return str + 3; } - if (memcmp(str, "-inf", 4) == 0) + // Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley + //if (memcmp(str, "-inf", 4) == 0) + if (strncmp(str, "-inf", 4) == 0) + // { *(U64 *)dest = 0xFFF0000000000000ll; return str + 4; } - if (memcmp(str, "1.#INF", 6) == 0) + // Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley + //if (memcmp(str, "1.#INF", 6) == 0) + if (strncmp(str, "1.#INF", 6) == 0) + // { *(U64 *)dest = 0x7FF0000000000000ll; return str + 6; } - if (memcmp(str, "-1.#INF", 7) == 0) + // Fix potential heap buffer overflow from using memcmp in llxmlnode; by Cinder Roxley + //if (memcmp(str, "-1.#INF", 7) == 0) + if (strncmp(str, "-1.#INF", 7) == 0) + // { *(U64 *)dest = 0xFFF0000000000000ll; return str + 7;