]> git.ipfire.org Git - thirdparty/sqlite.git/commitdiff
Fix another small buffer overread in sqlite_dbdata triggered by a corrupt database...
authordan <dan@noemail.net>
Thu, 9 May 2019 18:37:37 +0000 (18:37 +0000)
committerdan <dan@noemail.net>
Thu, 9 May 2019 18:37:37 +0000 (18:37 +0000)
FossilOrigin-Name: 1dfc95b8673b0e8c9ef5040c2fa0fbe9846e430d104e9b83f3f1f3ad63446380

ext/misc/dbdata.c
manifest
manifest.uuid

index a77519a1c3eb5eec548b1b1c61033ffced5884e3..7405e7c8909c6c043a8633d7fa856c3cd18a3391 100644 (file)
@@ -81,6 +81,8 @@ SQLITE_EXTENSION_INIT1
 #include <string.h>
 #include <assert.h>
 
+#define DBDATA_PADDING_BYTES 100 
+
 typedef struct DbdataTable DbdataTable;
 typedef struct DbdataCursor DbdataCursor;
 
@@ -334,12 +336,13 @@ static int dbdataLoadPage(
     int nCopy = sqlite3_column_bytes(pStmt, 0);
     if( nCopy>0 ){
       u8 *pPage;
-      pPage = (u8*)sqlite3_malloc64(nCopy);
+      pPage = (u8*)sqlite3_malloc64(nCopy + DBDATA_PADDING_BYTES);
       if( pPage==0 ){
         rc = SQLITE_NOMEM;
       }else{
         const u8 *pCopy = sqlite3_column_blob(pStmt, 0);
         memcpy(pPage, pCopy, nCopy);
+        memset(&pPage[nCopy], 0, DBDATA_PADDING_BYTES);
       }
       *ppPage = pPage;
       *pnPage = nCopy;
@@ -572,9 +575,9 @@ static int dbdataNext(sqlite3_vtab_cursor *pCursor){
             /* Allocate space for payload. And a bit more to catch small buffer
             ** overruns caused by attempting to read a varint or similar from 
             ** near the end of a corrupt record.  */
-            pCsr->pRec = (u8*)sqlite3_malloc64(nPayload+100);
+            pCsr->pRec = (u8*)sqlite3_malloc64(nPayload+DBDATA_PADDING_BYTES);
             if( pCsr->pRec==0 ) return SQLITE_NOMEM;
-            memset(pCsr->pRec, 0, nPayload+100);
+            memset(pCsr->pRec, 0, nPayload+DBDATA_PADDING_BYTES);
             pCsr->nRec = nPayload;
 
             /* Load the nLocal bytes of payload */
index 14e04a3cba76c5842861e0363e7fe3e78365d70a..dbc56151c5acaa80e549aa203644a387ace6b569 100644 (file)
--- a/manifest
+++ b/manifest
@@ -1,5 +1,5 @@
-C Fix\sa\sproblem\sin\sthe\s".recover"\scommand\sallowing\sa\scircular\sloop\sof\sb-tree\spages\sin\sa\sdatabase\sfile\sto\scause\san\sinfinite\sloop.
-D 2019-05-09T18:33:32.129
+C Fix\sanother\ssmall\sbuffer\soverread\sin\ssqlite_dbdata\striggered\sby\sa\scorrupt\sdatabase\spage.
+D 2019-05-09T18:37:37.967
 F .fossil-settings/empty-dirs dbb81e8fc0401ac46a1491ab34a7f2c7c0452f2f06b54ebb845d024ca8283ef1
 F .fossil-settings/ignore-glob 35175cdfcf539b2318cb04a9901442804be81cd677d8b889fcc9149c21f239ea
 F LICENSE.md df5091916dbb40e6e9686186587125e1b2ff51f022cc334e886c19a0e9982724
@@ -284,7 +284,7 @@ F ext/misc/closure.c dbfd8543b2a017ae6b1a5843986b22ddf99ff126ec9634a2f4047cd14c8
 F ext/misc/completion.c cec672d40604075bb341a7f11ac48393efdcd90a979269b8fe7977ea62d0547f
 F ext/misc/compress.c dd4f8a6d0baccff3c694757db5b430f3bbd821d8686d1fc24df55cf9f035b189
 F ext/misc/csv.c 7f047aeb68f5802e7ce6639292095d622a488bb43526ed04810e0649faa71ceb
-F ext/misc/dbdata.c f779a2e95ecc4fd05b97707bd972746bd851abfcd49316e92ff2da3a14aa690c
+F ext/misc/dbdata.c e316fba936571584e55abd5b974a32a191727a6b746053a0c9d439bd2cf93940
 F ext/misc/dbdump.c baf6e37447c9d6968417b1cd34cbedb0b0ab3f91b5329501d8a8d5be3287c336
 F ext/misc/eval.c 4b4757592d00fd32e44c7a067e6a0e4839c81a4d57abc4131ee7806d1be3104e
 F ext/misc/explain.c d5c12962d79913ef774b297006872af1fccda388f61a11d37758f9179a09551f
@@ -1825,7 +1825,7 @@ F vsixtest/vsixtest.tcl 6a9a6ab600c25a91a7acc6293828957a386a8a93
 F vsixtest/vsixtest.vcxproj.data 2ed517e100c66dc455b492e1a33350c1b20fbcdc
 F vsixtest/vsixtest.vcxproj.filters 37e51ffedcdb064aad6ff33b6148725226cd608e
 F vsixtest/vsixtest_TemporaryKey.pfx e5b1b036facdb453873e7084e1cae9102ccc67a0
-P f22c7e229ea4626c5268d61de3964521cf6a2735290cbd1518d68731ba6cca90
-R 70c45f240fec796aded79e59d457750f
+P 8d2a062eb8a3e6fdc6a61b571c8da0070382bf208c53e797151eac8679c975a1
+R 2de2a3768dbf383fc97e924a35530746
 U dan
-Z 7501180db88c65f34b6ae32d14e8f948
+Z 9056fece1b5cad0dc370fe823762d792
index 1f3b052a7b327e2a104bb66ce03f75b9acf67669..72b414a6e058fda9778c4b07ac1d915d74609105 100644 (file)
@@ -1 +1 @@
-8d2a062eb8a3e6fdc6a61b571c8da0070382bf208c53e797151eac8679c975a1
\ No newline at end of file
+1dfc95b8673b0e8c9ef5040c2fa0fbe9846e430d104e9b83f3f1f3ad63446380
\ No newline at end of file