mirror of
https://github.com/rakshasa/rtorrent.git
synced 2026-10-04 21:29:21 +00:00
Guard the unit multiplication in value commands against overflow.
The kb variants multiply the argument by 1024 without checking the range.
This commit is contained in:
+8
-1
@@ -2,6 +2,7 @@
|
||||
|
||||
#include <cstring>
|
||||
#include <cstdio>
|
||||
#include <limits>
|
||||
#include <locale>
|
||||
#include <torrent/exceptions.h>
|
||||
|
||||
@@ -136,7 +137,13 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
|
||||
// case ' ':
|
||||
// case '\0': *value = *value * unit; break;
|
||||
// default: throw torrent::input_error("Could not parse value.");
|
||||
default: *value = *value * unit; break;
|
||||
default:
|
||||
if (*value > std::numeric_limits<int64_t>::max() / unit ||
|
||||
*value < std::numeric_limits<int64_t>::min() / unit)
|
||||
return src; // overflow guard
|
||||
|
||||
*value = *value * unit;
|
||||
break;
|
||||
}
|
||||
|
||||
return last;
|
||||
|
||||
Reference in New Issue
Block a user