[MDEV-7019] String::chop() is wrong and may potentially crash. Created: 2014-11-03 Updated: 2014-11-10 Resolved: 2014-11-10 |
|
| Status: | Closed |
| Project: | MariaDB Server |
| Component/s: | OTHER |
| Affects Version/s: | 5.5.40, 10.0.14 |
| Fix Version/s: | 5.5.41 |
| Type: | Bug | Priority: | Major |
| Reporter: | Alexander Barkov | Assignee: | Alexander Barkov |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | upstream | ||
| Description |
|
Olivier noticed that this code looks wrong in sql_string.h:
it should be written as:
The reason why the problem was not found is probably because all chop() callers do not really care about correct 0-termination, they only need to reduce length by 1. Perhaps it should be fixed not to maintain 0 termination at all, to something like this:
|
| Comments |
| Comment by Alexander Barkov [ 2014-11-10 ] |
|
Upstream bug: |
| Comment by Alexander Barkov [ 2014-11-10 ] |
|
Pushed into 5.5. |