Re: [PATCH] svfwscanf: Simplify _sungetwc_r to eliminate apparent buffer overflow

Keith Packard <[email protected]>
Newsgroups gmane.comp.lib.newlib
Message-ID <[email protected]>
Corinna Vinschen <[email protected]> writes:

> Given all chars are sizeof(wchar_t), how's the buffer ever going to
> become unaligned?

It places the wchar_t at the end of _ubuf, which is 3 bytes long, making
it unaligned:

  fp->_p = &fp->_ubuf[sizeof (fp->_ubuf) - sizeof (wchar_t)];

-- 
-keith
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEw4O3eCVWE9/bQJ2R2yIaaQAAABEFAmEedgcACgkQ2yIaaQAA
ABGRxw/+KKGGhAY9oAApCkeU/IqSo/xHf/VOd/LUeBNc5CBKWUDynW1i9R2es8fv
M+EZ7qKQ6PHeTewx3J0AP7X1DUDEgw9sZP4btib39w28syHWkumcDMYn90mA3bWd
wFsIOnx+bsNlr+Kypepm/2SxoKkTyzLP4edHmFIwoe95/UqbNkmQL6QUt597QM0G
pO7nuuUDY83nceKVISxDDPMxYWv/BSWqtGkNBG5dy3XdW7yBjIraZiO0/Uk179u2
cHj2y8A0B5kqhvz50uCcFOybkASr0eX77mgllmft6iZT+fdB7DQkxxuYUJpxcIgP
p4XkonH+q5C44MYoTKzET3KaUAfu013nA+p4KmIvsYphj34yCrG7qSM7Wviz6rSx
/ra3HNd6rju8I8gKGPOFUlmxGEoWYDs6qdvXm+/UQgvD+8gJY3kIixiyhs1wpQuV
IvIfInJuePBY7NW9rTjHR3u1Q0KEm5T6shOh4IxNlOr8MmeCmfbr58iNpw/m5c3I
PJlh73bIgJlOv560fKJ6KcpGwXGuwy9xB3Y50bZbL5AvO/+AM54Z92Ih9AHuuW7W
Y3iNdBjMvxZOSCY4Mh5L6Ixq3oU5K8nraLYo2TVrY8c7+fE4F5ztO7NaCzIXGmfM
l2puyvpyQaQ6tZv0KVh9aV0RQV+IsVk693LwsZ+3DLbMyEbjYX0=
=TC8h
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.