Re: Fwd: report 1/3: buffer under-read in rfc2047.c lwslen()

"Kevin J. McCarthy" <[email protected]> Thu, 18 Jun 2026 08:13:35 +0800
Newsgroups gmane.mail.mutt.devel
Message-ID <[email protected]>
On Thu, Jun 18, 2026 at 08:09:01AM +0800, Kevin J. McCarthy wrote:
>From: Acts1631 <[email protected]>
>The lwslen() helper calculates the length of linear whitespace at the beginning of a string. It scans until the first non-whitespace character, then evaluates *(p - 1):
>
>  for (; p < s + n; p++)
>    if (!strchr(" \t\r\n", *p))
>    {
>      len = (size_t)(p - s);
>      break;
>    }
>  if (strchr("\r\n", *(p-1)))
>    len = (size_t)0;

This relies on 1) a invalid rfc2047 encodeed word (because the spec says 
there must be LWN) and 2) an obscure option being set, which defaults 
off.

However, the bug report is valid.  Mutt will under-read the buffer.

-- 
Kevin J. McCarthy
GPG Fingerprint: 8975 A9B3 3AA3 7910 385C  5308 ADEF 7684 8031 6BDA
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAmozOC8ACgkQre92hIAx
a9pmuA//bhKpI97ChdCNHo4IEwSAsgBNkffryDOvJ7fCr2sKb4GPHNYYVMDgrLhX
QYfozs6ve5h6du1vNpftPVbtPJKI45ZpG6EVmT7OY2dEItcUIzmz82IBTGOxMogi
seo+yYL6YdYFJPeF/JYqAC+JiJMxCOM3zKMFBqVhryW3GEkvolctrd9EproDo7Na
5UOQaLWWYZgzVJxU3LmN3936GuyjmP20ndiEh2yUt24GPNohjQcZbbkiXA8pwNVs
qWDdnF3yFIBr4sd3ZzYmEReERDAQoRnWw8qmpajXWiJqG4csoTb/keZuS5c1cf6W
e4fMTqEE6A1wV1dqjjcgy4fJpPVqtsirMUOCoUdqXUxrZWGoOR84DfGQRpFZdAy1
747jIgLtTc2Y+qtoqow6QVe0AUvmjhLeiH7InHb0VhiY2LdB7S+wXR/Px7yTjdRa
WcHyJ7RHC2hVYy/bsEo3HOaVi/Q8gUQLY3TvDJ9Jis4h86t50kRmSxn6Hk3EZDFE
i2gnT+ikw9C73sN7w7DhWaUbNSh54TsXX/JJEG87/zedWALVo9C91LJPKnEktXfq
5OfPE4XiKktsMceI+idATFrOVMF1OJy9JhLPlpQqkwVYeoLKc/MoxGhums1gFUvq
eekqnvSmg3+mJlSMpn8qmL44CHAH3K4p7ieV/4pCufcGfIDRKrU=
=HTmL
-----END PGP SIGNATURE-----