mirror of
https://github.com/vim/vim.git
synced 2025-09-25 03:54:15 -04:00
patch 9.1.0017: [security]: use-after-free in eval1_emsg()
Problem: use-after-free in eval1_emsg() when an empty line follows a lambda (by @yu3s) Solution: only set evalarg->eval_using_cmdline = FALSE when the *arg pointer is not null fixes: #13833 closes: #13841 Signed-off-by: Yegappan Lakshmanan <yegappan@yahoo.com> Signed-off-by: Christian Brabandt <cb@256bit.org>
This commit is contained in:
committed by
Christian Brabandt
parent
71d0ba07a3
commit
28d71b566a
11
src/eval.c
11
src/eval.c
@@ -2699,6 +2699,9 @@ eval_next_non_blank(char_u *arg, evalarg_T *evalarg, int *getnext)
|
||||
/*
|
||||
* To be called after eval_next_non_blank() sets "getnext" to TRUE.
|
||||
* Only called for Vim9 script.
|
||||
*
|
||||
* If "arg" is not NULL, then the caller should assign the return value to
|
||||
* "arg".
|
||||
*/
|
||||
char_u *
|
||||
eval_next_line(char_u *arg, evalarg_T *evalarg)
|
||||
@@ -2747,8 +2750,12 @@ eval_next_line(char_u *arg, evalarg_T *evalarg)
|
||||
}
|
||||
|
||||
// Advanced to the next line, "arg" no longer points into the previous
|
||||
// line.
|
||||
evalarg->eval_using_cmdline = FALSE;
|
||||
// line. The caller assigns the return value to "arg".
|
||||
// If "arg" is NULL, then the return value is discarded. In that case,
|
||||
// "arg" still points to the previous line. So don't reset
|
||||
// "eval_using_cmdline".
|
||||
if (arg != NULL)
|
||||
evalarg->eval_using_cmdline = FALSE;
|
||||
return skipwhite(line);
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user