Update of bug #68681 (group groff):

                  Status:             In Progress => Fixed
                 Privacy:                 Private => Public

    _______________________________________________________

Follow-up Comment #4:


commit 765d6cf03cdeb667627c3644bdd74e3b2afbddb9
Author: G. Branden Robinson <[email protected]>
Date:   Fri Sep 11 01:05:04 2026 -0500

    [refer]: Regression-test Savannah #68681.
    
    * src/preproc/refer/tests/check-index-file-validity.sh: Do it.

commit 5b228fbfc8ad4878f9795fa8f855bd354279e903
Author: G. Branden Robinson <[email protected]>
Date:   Thu Sep 10 06:46:18 2026 -0500

    [libbib]: Fix Savannah #68681.
    
    * src/libs/libbib/index.cpp (index_search_item::load): Check index file
      contents for nonsense: a string pool that begins with a null byte.  If
      it does, throw error diagnostic and return `false`, ignoring the index
      file and falling back to the plain text bibliographic database.  This
      prevents us from overreading the memory-mapped index file by one byte
      in the event it was truncated right after that null byte (due to
      nested use of strchr(3) and pointer arithmetic).
    
    Fixes <https://savannah.gnu.org/bugs/?68681>.  Thanks to Pavol Sloboda
    for the report and analysis.  Problem dates back to groff's birth.  (And
    I didn't catch it when doing the work for commit 1b97881fc0,
    2021-09-12.)




    _______________________________________________________

Reply to this item at:

  <https://savannah.gnu.org/bugs/?68681>

_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/

Attachment: signature.asc
Description: PGP signature

Reply via email to