mirror of
https://github.com/nlohmann/json.git
synced 2026-10-10 16:37:14 +00:00
Fix out-of-bounds read when dumping a float token of an unchecked image
A float node of an image loaded with image_check::bounds can hold a token whose bytes are not digits, so its value need not have the digit count recorded in the node. write_double_at() passed that count to write_short_decimal(), which indexes its table of powers of ten by it: an assertion failure in debug builds, an out-of-bounds read in release builds. Use the counted overload only if the value has exactly that many digits, otherwise count them. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
2 files changed
+33
-3
No files matched your search
@@ -712,6 +712,31 @@ TEST_CASE("json_view images: check")
|
||||
}
|
||||
}
|
||||
|
||||
SECTION("float tokens with fewer digits than the layout records")
|
||||
{
|
||||
// The bytes of the token are not digits (they read as zeros or as
|
||||
// other values), so the value has fewer (or more) digits than the
|
||||
// layout says: dump() must still write a number.
|
||||
for (const auto& source : std::vector<std::pair<std::string, std::string>>
|
||||
{
|
||||
{"123456789012345678.5", std::string("@") + std::string(16, '0') + "1.1"}, // 19 digits
|
||||
{"1234.5", "@001.1"}, // 5 digits
|
||||
{"1234.5", "9??.??"} // more than 5 digits
|
||||
})
|
||||
{
|
||||
CAPTURE(source.second)
|
||||
const std::vector<std::uint8_t> img = json_document::parse("[" + source.first + "]").save();
|
||||
const node n = node_at(img, 1);
|
||||
REQUIRE(source.second.size() == n.len);
|
||||
std::vector<std::uint8_t> b = img;
|
||||
std::memcpy(b.data() + text_at(img) + n.off, source.second.data(), n.len);
|
||||
const json_document d = json_document::load(b, image_check::bounds);
|
||||
const std::string dumped = d.root().dump();
|
||||
CAPTURE(dumped)
|
||||
CHECK(json::parse(dumped)[0].is_number());
|
||||
}
|
||||
}
|
||||
|
||||
SECTION("integer ranges")
|
||||
{
|
||||
// tokens of many digits, which the parser stores as floats
|
||||
|
||||
Reference in new issue
Block a user