antirez / antirez/sds

Null Dereferences v2.0.0

Abierto
#99 2 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
C
Estrellas
5.6k
Forks
510
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

In many functions in file “sds.h”, the parameter “sds s” is dereferenced without checking if it is NULL. The same error is also present in some functions in file “sds.c”, such as: `sdscat`, `sdsMakeRoomFor`, `sdsRemoveFreeSpace`, `sdsdup`, `sdsupdatelen`, `sdscatrepr`, `sdscmp`, `sdstoupper`, `sdstolower`, `sdsrange`, `sdstrim`, `sdscatfmt`, `sdsclear`, `sdslen`, `sdscatvprintf`, `sdscatprintf`, `sdscpy`, `sdscpylen`, `sdscatsds`, `sdscatlen`, `sdsgrowzero`, `sdsIncrLen`, `sdsAllocSize` e `sdsAllocPtr`.

This functions should check for a parameter with value NULL and possibly return an error code in such case.

Minimal example:

```C
int sdsTest(void) {
sds x = NULL;
test_cond("Create a string and obtain the length",
sdslen(x) == 3 && memcmp(x,"foo\0",4) == 0)

sdsfree(x);
test_report();
return 0;
}
```

Forcing the variable “sds s = NULL” while running the test programs generates a segmentation fault (due to the attempt to dereference NULL).

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.