summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristoph M. Becker <cmbecker69@gmx.de>2020-01-26 16:03:35 +0100
committerDerick Rethans <github@derickrethans.nl>2020-02-18 09:48:25 +0000
commitb97a9718c83380eff20ae1be22f2a5a4f7a53d89 (patch)
tree9b9478f81abaf19a1d48f1b98f58e0dc5bf59427
parente73d8e2627e6e0aa91441ffa745661c6664906f1 (diff)
downloadphp-git-b97a9718c83380eff20ae1be22f2a5a4f7a53d89.tar.gz
Fix # 79171: heap-buffer-overflow in phar_extract_file
We must not access memory outside of the allocated buffer.
-rw-r--r--ext/phar/phar_object.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/ext/phar/phar_object.c b/ext/phar/phar_object.c
index 89b553c2b9..eaa74ece94 100644
--- a/ext/phar/phar_object.c
+++ b/ext/phar/phar_object.c
@@ -4184,7 +4184,7 @@ static int phar_extract_file(zend_bool overwrite, phar_entry_info *entry, char *
if ('\\' == filename[cnt]) {
filename[cnt] = '/';
}
- } while (cnt++ <= filename_len);
+ } while (cnt++ < filename_len);
}
#endif