builtin/mv: fix out of bounds write

When commit a88c915 (mv: move submodules using a gitfile, 2013-07-30) added the submodule_gitfile array, it was not added to the block that enlarges the arrays when we are moving a directory so that we do not have to worry about it being a directory when we perform the actual move. After this, the loop continues over the enlarged set of sources. Since we assume that submodule_gitfile has size argc, if any of the items in the source directory are submodules we are guaranteed to write beyond the end of submodule_gitfile. Fix this by realloc'ing submodule_gitfile at the same time as the other arrays. Reported-by: Guillaume Gelin <contact@ramnes.eu> Signed-off-by: John Keeping <john@keeping.me.uk> Signed-off-by: Junio C Hamano <gitster@pobox.com>

John Keeping committed Mar 8, 2014 at 19:29 UTC 89ccc1b09cf4004e6129c66def42b47206ed6b5f
1 file changed +4
builtin/mv.c
+4
@@ -179,6 +179,9 @@ int cmd_mv(int argc, const char **argv, const char *prefix)
179 modes = xrealloc(modes,
180 (argc + last - first)
181 * sizeof(enum update_mode));
182 + submodule_gitfile = xrealloc(submodule_gitfile,
183 + (argc + last - first)
184 + * sizeof(char *));
185 }
186
187 dst = add_slash(dst);
@@ -192,6 +195,7 @@ int cmd_mv(int argc, const char **argv, const char *prefix)
195 prefix_path(dst, dst_len,
196 path + length + 1);
197 modes[argc + j] = INDEX;
198 + submodule_gitfile[argc + j] = NULL;
199 }
200 argc += last - first;
201 }