mirror of
https://github.com/rakshasa/rtorrent.git
synced 2026-10-05 05:39:22 +00:00
Guard the unit multiplication in value commands against overflow.
The kb variants multiply the argument by 1024 without checking the range.
This commit is contained in:
+9
-1
@@ -1,5 +1,7 @@
|
||||
#include "config.h"
|
||||
|
||||
#include <limits>
|
||||
|
||||
#include "core/download.h"
|
||||
#include "parse.h"
|
||||
|
||||
@@ -41,7 +43,13 @@ command_base_call_value_base(command_base* command_raw, target_type target, cons
|
||||
return command_base::_call<typename command_value_function<T>::type, T>(command_raw, target, val);
|
||||
}
|
||||
|
||||
return command_base::_call<typename command_value_function<T>::type, T>(command_raw, target, unit * arg.as_value());
|
||||
auto value = arg.as_value();
|
||||
|
||||
if (value > std::numeric_limits<int64_t>::max() / unit ||
|
||||
value < std::numeric_limits<int64_t>::min() / unit)
|
||||
throw torrent::input_error("Value out of range.");
|
||||
|
||||
return command_base::_call<typename command_value_function<T>::type, T>(command_raw, target, unit * value);
|
||||
}
|
||||
|
||||
template <typename T> const torrent::Object
|
||||
|
||||
+8
-1
@@ -2,6 +2,7 @@
|
||||
|
||||
#include <cstring>
|
||||
#include <cstdio>
|
||||
#include <limits>
|
||||
#include <locale>
|
||||
#include <torrent/exceptions.h>
|
||||
|
||||
@@ -136,7 +137,13 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
|
||||
// case ' ':
|
||||
// case '\0': *value = *value * unit; break;
|
||||
// default: throw torrent::input_error("Could not parse value.");
|
||||
default: *value = *value * unit; break;
|
||||
default:
|
||||
if (*value > std::numeric_limits<int64_t>::max() / unit ||
|
||||
*value < std::numeric_limits<int64_t>::min() / unit)
|
||||
return src; // overflow guard
|
||||
|
||||
*value = *value * unit;
|
||||
break;
|
||||
}
|
||||
|
||||
return last;
|
||||
|
||||
Reference in New Issue
Block a user