From dd692d9cea5335b181d877ae917fe6e75587a812 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tim=20R=C3=BChsen?= Date: Mon, 29 Jun 2026 19:13:15 +0200 Subject: [PATCH] * src/convert.c (html_quote_string): Fix integer+buffer overflow Reported-by: TristanInSec@gmail.com Upstream commit (GitLab mirror): https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812 --- wget-1.25.0/src/convert.c +++ wget-1.25.0/src/convert.c @@ -36,6 +36,7 @@ #include #include #include #include +#include #include "convert.h" #include "url.h" #include "recur.h" @@ -1178,21 +1179,37 @@ html_quote_string (const char *s) { const char *b = s; char *p, *res; - int i; + size_t i; + int ok; /* Pass through the string, and count the new size. */ - for (i = 0; *s; s++, i++) + for (i = 0; *s; s++) { if (*s == '&') - i += 4; /* `amp;' */ + ok = INT_ADD_OK (i, 4, &i); /* `amp;' */ else if (*s == '<' || *s == '>') - i += 3; /* `lt;' and `gt;' */ + ok = INT_ADD_OK (i, 3, &i); /* `lt;' and `gt;' */ else if (*s == '\"') - i += 5; /* `quot;' */ + ok = INT_ADD_OK (i, 5, &i); /* `quot;' */ else if (*s == ' ') - i += 4; /* #32; */ + ok = INT_ADD_OK (i, 4, &i); /* #32; */ + else + ok = INT_ADD_OK (i, 1, &i); + + if (!ok) + { + DEBUGP (("Overflow detected in html_quote_string().\n")); + abort(); + } } - res = xmalloc (i + 1); + + if (!INT_ADD_OK (i, 1, &i)) + { + DEBUGP (("Overflow detected in html_quote_string().\n")); + abort(); + } + + res = xmalloc (i); s = b; for (p = res; *s; s++) {