forked from aniani/vim
patch 8.2.3741: using freed memory in open command
Problem: Using freed memory in open command. Solution: Make a copy of the current line.
This commit is contained in:
@@ -6877,13 +6877,17 @@ ex_open(exarg_T *eap)
|
|||||||
regmatch.regprog = vim_regcomp(eap->arg, magic_isset() ? RE_MAGIC : 0);
|
regmatch.regprog = vim_regcomp(eap->arg, magic_isset() ? RE_MAGIC : 0);
|
||||||
if (regmatch.regprog != NULL)
|
if (regmatch.regprog != NULL)
|
||||||
{
|
{
|
||||||
|
// make a copy of the line, when searching for a mark it might be
|
||||||
|
// flushed
|
||||||
|
char_u *line = vim_strsave(ml_get_curline());
|
||||||
|
|
||||||
regmatch.rm_ic = p_ic;
|
regmatch.rm_ic = p_ic;
|
||||||
p = ml_get_curline();
|
if (vim_regexec(®match, line, (colnr_T)0))
|
||||||
if (vim_regexec(®match, p, (colnr_T)0))
|
curwin->w_cursor.col = (colnr_T)(regmatch.startp[0] - line);
|
||||||
curwin->w_cursor.col = (colnr_T)(regmatch.startp[0] - p);
|
|
||||||
else
|
else
|
||||||
emsg(_(e_nomatch));
|
emsg(_(e_nomatch));
|
||||||
vim_regfree(regmatch.regprog);
|
vim_regfree(regmatch.regprog);
|
||||||
|
vim_free(line);
|
||||||
}
|
}
|
||||||
// Move to the NUL, ignore any other arguments.
|
// Move to the NUL, ignore any other arguments.
|
||||||
eap->arg += STRLEN(eap->arg);
|
eap->arg += STRLEN(eap->arg);
|
||||||
|
@@ -121,6 +121,19 @@ func Test_open_command()
|
|||||||
close!
|
close!
|
||||||
endfunc
|
endfunc
|
||||||
|
|
||||||
|
func Test_open_command_flush_line()
|
||||||
|
" this was accessing freed memory: the regexp match uses a pointer to the
|
||||||
|
" current line which becomes invalid when searching for the ') mark.
|
||||||
|
new
|
||||||
|
call setline(1, ['one', 'two. three'])
|
||||||
|
s/one/ONE
|
||||||
|
try
|
||||||
|
open /\%')/
|
||||||
|
catch /E479/
|
||||||
|
endtry
|
||||||
|
bwipe!
|
||||||
|
endfunc
|
||||||
|
|
||||||
" Test for :g/pat/visual to run vi commands in Ex mode
|
" Test for :g/pat/visual to run vi commands in Ex mode
|
||||||
" This used to hang Vim before 8.2.0274.
|
" This used to hang Vim before 8.2.0274.
|
||||||
func Test_Ex_global()
|
func Test_Ex_global()
|
||||||
|
@@ -753,6 +753,8 @@ static char *(features[]) =
|
|||||||
|
|
||||||
static int included_patches[] =
|
static int included_patches[] =
|
||||||
{ /* Add new patch number below this line */
|
{ /* Add new patch number below this line */
|
||||||
|
/**/
|
||||||
|
3741,
|
||||||
/**/
|
/**/
|
||||||
3740,
|
3740,
|
||||||
/**/
|
/**/
|
||||||
|
Reference in New Issue
Block a user