Update of bug #68684 (group groff):

                  Status:             In Progress => Fixed
                 Privacy:                 Private => Public
             Open/Closed:                    Open => Closed

    _______________________________________________________

Follow-up Comment #4:


commit 864a79816d9c52ee38e81560b11f790b1bd1bac9
Author: G. Branden Robinson <[email protected]>
Date:   Wed Sep 30 02:55:50 2026 -0500

    [hpftodit]: Regression test Savannah #68684.
    
    * src/utils/hpftodit/tests/handles-font-names-carefully.sh: Do it.
    
    * src/utils/hpftodit/hpftodit.am (hpftodit_TESTS): Run test.
    
    Test fails at this commit.

commit 3315594545f224698b312bedfb19dec379110611
Author: G. Branden Robinson <[email protected]>
Date:   Wed Sep 30 02:13:48 2026 -0500

    [hpftodit]: Fix Savannah #68684.
    
    * src/utils/hpftodit/hpftodit.cpp (output_font_name): Heavily revise to
      more carefully validate TFM input file and manage memory.  Fatally
      error out upon reading a font name length claimed by the file that is
      absurd, avoiding unpredictable, input-driven heap memory allocation.
      Zero out the heap-allocated buffer immediately.  Fatally error out
      upon reading a font name that starts with whitespace character.
      Rewrite trailing whitespace-stripping loop to avoid overwriting and
      backwards-overreading the buffer.
    
    Fixes <https://savannah.gnu.org/bugs/?68684>.  Thanks to Pavol Sloboda
    for the report and a reproducer.  Problem appears to date back to commit
    65a386ebce, 2003-12-27.




    _______________________________________________________

Reply to this item at:

  <https://savannah.gnu.org/bugs/?68684>

_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/

Attachment: signature.asc
Description: PGP signature

Reply via email to