mirror of
https://github.com/neovim/neovim.git
synced 2025-10-04 17:06:30 +00:00
vim-patch:9.0.2111: [security]: overflow in get_number
Problem: [security]: overflow in get_number
Solution: Return 0 when the count gets too large
[security]: overflow in get_number
When using the z= command, we may overflow the count with values larger
than MAX_INT. So verify that we do not overflow and in case when an
overflow is detected, simply return 0
73b2d3790c
Co-authored-by: Christian Brabandt <cb@256bit.org>
This commit is contained in:
@@ -180,6 +180,9 @@ int get_number(int colon, int *mouse_used)
|
||||
ui_cursor_goto(msg_row, msg_col);
|
||||
int c = safe_vgetc();
|
||||
if (ascii_isdigit(c)) {
|
||||
if (n > INT_MAX / 10) {
|
||||
return 0;
|
||||
}
|
||||
n = n * 10 + c - '0';
|
||||
msg_putchar(c);
|
||||
typed++;
|
||||
|
Reference in New Issue
Block a user