fast-import: fix buffer overflow in dump_tags
When creating a new annotated tag, we sprintf the refname into a static-sized buffer. If we have an absurdly long tagname, like: git init repo && cd repo && git commit --allow-empty -m foo && git tag -m message mytag && git fast-export mytag | perl -lpe '/^tag/ and s/mytag/"a" x 8192/e' | git fast-import <input we'll overflow the buffer. We can fix it by using a strbuf. Signed-off-by: Jeff King <peff@peff.net> Reviewed-by: Michael Haggerty <mhagger@alum.mit.edu> Reviewed-by: Ronnie Sahlberg <sahlberg@google.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Aug 23, 2014 at 01:32 UTC
c252785982c268e5c969900c677322744d09f52e
1 file changed
+6
-4
fast-import.c
+6
-4
@@ -1730,14 +1730,16 @@ static void dump_tags(void)
1730
static const char *msg = "fast-import";
1731
struct tag *t;
1732
struct ref_lock *lock;
1733
- char ref_name[PATH_MAX];
1733
+ struct strbuf ref_name = STRBUF_INIT;
1734
1735
for (t = first_tag; t; t = t->next_tag) {
1736
- sprintf(ref_name, "tags/%s", t->name);
1737
- lock = lock_ref_sha1(ref_name, NULL);
1736
+ strbuf_reset(&ref_name);
1737
+ strbuf_addf(&ref_name, "tags/%s", t->name);
1738
+ lock = lock_ref_sha1(ref_name.buf, NULL);
1739
if (!lock || write_ref_sha1(lock, t->sha1, msg) < 0)
1739
- failure |= error("Unable to update %s", ref_name);
1740
+ failure |= error("Unable to update %s", ref_name.buf);
1741
}
1742
+ strbuf_release(&ref_name);
1743
}
1744
1745
static void dump_marks_helper(FILE *f,