Karsten Hopp e5d49e
To: vim_dev@googlegroups.com
Karsten Hopp e5d49e
Subject: Patch 7.3.809
Karsten Hopp e5d49e
Fcc: outbox
Karsten Hopp e5d49e
From: Bram Moolenaar <Bram@moolenaar.net>
Karsten Hopp e5d49e
Mime-Version: 1.0
Karsten Hopp e5d49e
Content-Type: text/plain; charset=UTF-8
Karsten Hopp e5d49e
Content-Transfer-Encoding: 8bit
Karsten Hopp e5d49e
------------
Karsten Hopp e5d49e
Karsten Hopp e5d49e
Patch 7.3.809
Karsten Hopp e5d49e
Problem:    The dosinst.c program has a buffer overflow. (Thomas Gwae)
Karsten Hopp e5d49e
Solution:   Ignore $VIMRUNTIME if it is too long.
Karsten Hopp e5d49e
Files:	    src/dosinst.c
Karsten Hopp e5d49e
Karsten Hopp e5d49e
Karsten Hopp e5d49e
*** ../vim-7.3.808/src/dosinst.c	2010-08-15 21:57:28.000000000 +0200
Karsten Hopp e5d49e
--- src/dosinst.c	2013-02-13 14:34:25.000000000 +0100
Karsten Hopp e5d49e
***************
Karsten Hopp e5d49e
*** 375,381 ****
Karsten Hopp e5d49e
  
Karsten Hopp e5d49e
      /* First get $VIMRUNTIME.  If it's set, remove the tail. */
Karsten Hopp e5d49e
      vim = getenv("VIMRUNTIME");
Karsten Hopp e5d49e
!     if (vim != NULL && *vim != 0)
Karsten Hopp e5d49e
      {
Karsten Hopp e5d49e
  	strcpy(buf, vim);
Karsten Hopp e5d49e
  	remove_tail(buf);
Karsten Hopp e5d49e
--- 375,381 ----
Karsten Hopp e5d49e
  
Karsten Hopp e5d49e
      /* First get $VIMRUNTIME.  If it's set, remove the tail. */
Karsten Hopp e5d49e
      vim = getenv("VIMRUNTIME");
Karsten Hopp e5d49e
!     if (vim != NULL && *vim != 0 && strlen(vim) < BUFSIZE)
Karsten Hopp e5d49e
      {
Karsten Hopp e5d49e
  	strcpy(buf, vim);
Karsten Hopp e5d49e
  	remove_tail(buf);
Karsten Hopp e5d49e
*** ../vim-7.3.808/src/version.c	2013-02-13 14:17:00.000000000 +0100
Karsten Hopp e5d49e
--- src/version.c	2013-02-13 14:36:33.000000000 +0100
Karsten Hopp e5d49e
***************
Karsten Hopp e5d49e
*** 727,728 ****
Karsten Hopp e5d49e
--- 727,730 ----
Karsten Hopp e5d49e
  {   /* Add new patch number below this line */
Karsten Hopp e5d49e
+ /**/
Karsten Hopp e5d49e
+     809,
Karsten Hopp e5d49e
  /**/
Karsten Hopp e5d49e
Karsten Hopp e5d49e
-- 
Karsten Hopp e5d49e
"I know that there are people who don't love their fellow man,
Karsten Hopp e5d49e
and I hate those people!" - Tom Lehrer
Karsten Hopp e5d49e
Karsten Hopp e5d49e
 /// Bram Moolenaar -- Bram@Moolenaar.net -- http://www.Moolenaar.net   \\\
Karsten Hopp e5d49e
///        sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
Karsten Hopp e5d49e
\\\  an exciting new programming language -- http://www.Zimbu.org        ///
Karsten Hopp e5d49e
 \\\            help me help AIDS victims -- http://ICCF-Holland.org    ///