Browse Source

tools: sunxi: avoid read after end of string

The evaluation of option -c is incorrect:

According to the C99 standard endptr in the first strtol is always
set as &endptr is not NULL.
So the first part of the or condition is always true.
If all digits in optarg are valid endptr will point to the closing \0
and the second strtol will read beyond the end of the string optarg
points to.

Signed-off-by: Heinrich Schuchardt <xypron.glpk@gmx.de>
Acked-by: Boris Brezillon <boris.brezillon@free-electrons.com>
tags/2020-06-01
xypron.glpk@gmx.de 4 years ago
committed by Tom Rini
parent
commit
f59a3b21f6
1 changed files with 1 additions and 1 deletions
  1. +1
    -1
      tools/sunxi-spl-image-builder.c

+ 1
- 1
tools/sunxi-spl-image-builder.c View File

@@ -433,7 +433,7 @@ int main(int argc, char **argv)
break;
case 'c':
info.ecc_strength = strtol(optarg, &endptr, 0);
if (endptr || *endptr == '/')
if (*endptr == '/')
info.ecc_step_size = strtol(endptr + 1, NULL, 0);
break;
case 'p':