]> git.ipfire.org Git - thirdparty/krb5.git/commit
Avoid small read overrun in UTF8 normalization
authorGreg Hudson <ghudson@mit.edu>
Wed, 12 Oct 2022 04:27:17 +0000 (00:27 -0400)
committerGreg Hudson <ghudson@mit.edu>
Thu, 3 Nov 2022 04:57:49 +0000 (00:57 -0400)
commitfb9cf8cfbf8da0d160cb61250b952f2b8e5484f4
tree2837ca13fc97c78dcf167f7b7398cf5e03d720c6
parent30429ade54bfe66f9145a30487e43b19bde76701
Avoid small read overrun in UTF8 normalization

In krb5int_utf8_normalize(), check the length of the current character
against the buffer length before reading more than one byte.  Credit
to OSS-Fuzz for discovering the overrun.

ticket: 9072 (new)
src/lib/krb5/unicode/ucstr.c