summaryrefslogtreecommitdiff
path: root/src/stdio/ungetc.c
diff options
context:
space:
mode:
authorRich Felker <dalias@aerifal.cx>2016-10-19 20:17:16 -0400
committerRich Felker <dalias@aerifal.cx>2016-10-19 20:17:16 -0400
commit70d2687d85c314963cf280759b23fd4573ff0d82 (patch)
treedbbd4b169245294bee78e30f33e1cc22c519be3d /src/stdio/ungetc.c
parentaee6abb2400b9a955c2b41166db1c22f63ad42ef (diff)
downloadmusl-70d2687d85c314963cf280759b23fd4573ff0d82.tar.gz
musl-70d2687d85c314963cf280759b23fd4573ff0d82.tar.bz2
musl-70d2687d85c314963cf280759b23fd4573ff0d82.tar.xz
musl-70d2687d85c314963cf280759b23fd4573ff0d82.zip
fix integer overflow in float printf needed-precision computation
if the requested precision is close to INT_MAX, adding LDBL_MANT_DIG/3+8 overflows. in practice the resulting undefined behavior manifests as a large negative result, which is then used to compute the new end pointer (z) with a wildly out-of-bounds value (more overflow, more undefined behavior). the end result is at least incorrect output and character count (return value); worse things do not seem to happen, but detailed analysis has not been done. this patch fixes the overflow by performing the intermediate computation as unsigned; after division by 9, the final result necessarily fits in int.
Diffstat (limited to 'src/stdio/ungetc.c')
0 files changed, 0 insertions, 0 deletions