Update of bug #68681 (group groff):
Status: In Progress => Fixed
Privacy: Private => Public
_______________________________________________________
Follow-up Comment #4:
commit 765d6cf03cdeb667627c3644bdd74e3b2afbddb9
Author: G. Branden Robinson <[email protected]>
Date: Fri Sep 11 01:05:04 2026 -0500
[refer]: Regression-test Savannah #68681.
* src/preproc/refer/tests/check-index-file-validity.sh: Do it.
commit 5b228fbfc8ad4878f9795fa8f855bd354279e903
Author: G. Branden Robinson <[email protected]>
Date: Thu Sep 10 06:46:18 2026 -0500
[libbib]: Fix Savannah #68681.
* src/libs/libbib/index.cpp (index_search_item::load): Check index file
contents for nonsense: a string pool that begins with a null byte. If
it does, throw error diagnostic and return `false`, ignoring the index
file and falling back to the plain text bibliographic database. This
prevents us from overreading the memory-mapped index file by one byte
in the event it was truncated right after that null byte (due to
nested use of strchr(3) and pointer arithmetic).
Fixes <https://savannah.gnu.org/bugs/?68681>. Thanks to Pavol Sloboda
for the report and analysis. Problem dates back to groff's birth. (And
I didn't catch it when doing the work for commit 1b97881fc0,
2021-09-12.)
_______________________________________________________
Reply to this item at:
<https://savannah.gnu.org/bugs/?68681>
_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/
signature.asc
Description: PGP signature
