From 54a872f0fac2d99ccfbad5e298c08ba8ccbb7931 Mon Sep 17 00:00:00 2001 From: Simon Date: Mon, 30 Apr 2018 16:41:02 -0700 Subject: [PATCH] Fix undefined behaviour, calling memcpy with NULL pointer. Identified as part of audit: Least Authority, Issue D. --- src/streams.h | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/src/streams.h b/src/streams.h index 624c0ce66..1623507d8 100644 --- a/src/streams.h +++ b/src/streams.h @@ -230,6 +230,10 @@ public: { if (nSize == 0) return; + if (pch == nullptr) { + throw std::ios_base::failure("CBaseDataStream::read(): cannot read from null pointer"); + } + // Read from the beginning of the buffer unsigned int nReadPosNext = nReadPos + nSize; if (nReadPosNext >= vch.size()) @@ -519,6 +523,12 @@ public: // read a number of bytes void read(char *pch, size_t nSize) { + if (nSize == 0) return; + + if (pch == nullptr) { + throw std::ios_base::failure("CBufferedFile::read(): cannot read from null pointer"); + } + if (nSize + nReadPos > nReadLimit) throw std::ios_base::failure("Read attempted past buffer limit"); if (nSize + nRewind > vchBuf.size())