mirror of
https://github.com/cesanta/mongoose.git
synced 2026-10-01 05:52:32 +07:00
Guard against NULL return in mg_file_printf
mg_vmprintf() returns io.buf from a mg_iobuf that starts empty. When the internal mg_iobuf_resize() allocation fails, the buffer is left NULL and mg_vmprintf() returns NULL. mg_file_printf() passed that result straight to strlen(data), dereferencing NULL on allocation failure. Skip the write when mg_vmprintf() returns NULL and return false, matching how the rest of the codebase checks mg_calloc()/allocation results.
This commit is contained in:
+4
-2
@@ -3046,8 +3046,10 @@ bool mg_file_printf(struct mg_fs *fs, const char *path, const char *fmt, ...) {
|
||||
va_start(ap, fmt);
|
||||
data = mg_vmprintf(fmt, &ap);
|
||||
va_end(ap);
|
||||
result = mg_file_write(fs, path, data, strlen(data));
|
||||
mg_free(data);
|
||||
if (data != NULL) {
|
||||
result = mg_file_write(fs, path, data, strlen(data));
|
||||
mg_free(data);
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
@@ -67,8 +67,10 @@ bool mg_file_printf(struct mg_fs *fs, const char *path, const char *fmt, ...) {
|
||||
va_start(ap, fmt);
|
||||
data = mg_vmprintf(fmt, &ap);
|
||||
va_end(ap);
|
||||
result = mg_file_write(fs, path, data, strlen(data));
|
||||
mg_free(data);
|
||||
if (data != NULL) {
|
||||
result = mg_file_write(fs, path, data, strlen(data));
|
||||
mg_free(data);
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user