Mercurial > hg
diff mercurial/scmwindows.py @ 38187:90a274965de7 stable
mpatch: be more careful about parsing binary patch data (SEC)
It appears to have been possible to trivially walk off the end of an
allocated region with a malformed patch. Oops.
Caught when writing an mpatch fuzzer for oss-fuzz.
This defect is OVE-20180430-0001. A CVE has not been obtained as of
this writing.
author | Augie Fackler <augie@google.com> |
---|---|
date | Sat, 28 Apr 2018 00:42:16 -0400 |
parents | e24802ea8dbd |
children | 57875cf423c9 |