Blame SOURCES/openslp-2.0.0-fortify-source-buffer-overflow.patch

5692fb
diff -up openslp-2.0.0/slpd/slpd_predicate.c.orig openslp-2.0.0/slpd/slpd_predicate.c
5692fb
--- openslp-2.0.0/slpd/slpd_predicate.c.orig	2012-12-11 00:31:53.000000000 +0100
5692fb
+++ openslp-2.0.0/slpd/slpd_predicate.c	2015-01-14 13:17:45.115104003 +0100
5692fb
@@ -1425,6 +1425,8 @@ void freePredicateParseTree(SLPDPredicat
5692fb
          break;
5692fb
       }
5692fb
       pNextNode = pNode->next;
5692fb
+      xfree(pNode->nodeBody.comparison.tag_str);
5692fb
+      xfree(pNode->nodeBody.comparison.value_str);
5692fb
       xfree(pNode);
5692fb
       pNode = pNextNode;
5692fb
    }
5692fb
@@ -1643,26 +1645,28 @@ SLPDPredicateParseResult createPredicate
5692fb
       rhs = val_start;
5692fb
 
5692fb
       /***** Create leaf node. *****/
5692fb
-      *ppNode = (SLPDPredicateTreeNode *)xmalloc(sizeof (SLPDPredicateTreeNode) + lhs_len + rhs_len);
5692fb
+      *ppNode = (SLPDPredicateTreeNode *)xmalloc(sizeof (SLPDPredicateTreeNode));
5692fb
       if (!(*ppNode))
5692fb
          return PREDICATE_PARSE_INTERNAL_ERROR;
5692fb
 
5692fb
+      (*ppNode)->nodeBody.comparison.tag_str = (char *)xmalloc((lhs_len+1) * sizeof(char));
5692fb
+      if (!((*ppNode)->nodeBody.comparison.tag_str))
5692fb
+         return PREDICATE_PARSE_INTERNAL_ERROR;
5692fb
+
5692fb
+      (*ppNode)->nodeBody.comparison.value_str = (char *)xmalloc((rhs_len+1) * sizeof(char));
5692fb
+      if (!((*ppNode)->nodeBody.comparison.value_str))
5692fb
+         return PREDICATE_PARSE_INTERNAL_ERROR;
5692fb
+
5692fb
       (*ppNode)->nodeType = op;
5692fb
       (*ppNode)->next = (SLPDPredicateTreeNode *)0;
5692fb
 
5692fb
-      /* Finished with "operator" now - just use as temporary pointer to assist with copying the
5692fb
-       * attribute name (lhs) and required value (rhs) into the node
5692fb
-       */
5692fb
-      operator = (*ppNode)->nodeBody.comparison.storage;
5692fb
-      strncpy(operator, lhs, lhs_len);
5692fb
-      operator[lhs_len] = '\0';
5692fb
       (*ppNode)->nodeBody.comparison.tag_len = lhs_len;
5692fb
-      (*ppNode)->nodeBody.comparison.tag_str = operator;
5692fb
-      operator += lhs_len + 1;
5692fb
-      strncpy(operator, rhs, rhs_len);
5692fb
-      operator[rhs_len] = '\0';
5692fb
+      strncpy((*ppNode)->nodeBody.comparison.tag_str, lhs, lhs_len);
5692fb
+      (*ppNode)->nodeBody.comparison.tag_str[lhs_len] = '\0';
5692fb
+
5692fb
       (*ppNode)->nodeBody.comparison.value_len = rhs_len;
5692fb
-      (*ppNode)->nodeBody.comparison.value_str = operator;
5692fb
+      strncpy((*ppNode)->nodeBody.comparison.value_str, rhs, rhs_len);
5692fb
+      (*ppNode)->nodeBody.comparison.value_str[rhs_len] = '\0';
5692fb
 
5692fb
       return PREDICATE_PARSE_OK;
5692fb
    }