1
0
mirror of https://gitlab.gnome.org/GNOME/libxml2.git synced 2025-03-27 18:50:07 +03:00

[CVE-2025-24928] Fix stack-buffer-overflow in xmlSnprintfElements

Fixes #847.
This commit is contained in:
Nick Wellnhofer 2025-02-11 17:30:40 +01:00
parent 5880a9a6bd
commit 8c8753ad52

22
valid.c
View File

@ -4997,26 +4997,26 @@ xmlSnprintfElements(char *buf, int size, xmlNodePtr node, int glob) {
return;
}
switch (cur->type) {
case XML_ELEMENT_NODE:
case XML_ELEMENT_NODE: {
int qnameLen = xmlStrlen(cur->name);
if ((cur->ns != NULL) && (cur->ns->prefix != NULL))
qnameLen += xmlStrlen(cur->ns->prefix) + 1;
if (size - len < qnameLen + 10) {
if ((size - len > 4) && (buf[len - 1] != '.'))
strcat(buf, " ...");
return;
}
if ((cur->ns != NULL) && (cur->ns->prefix != NULL)) {
if (size - len < xmlStrlen(cur->ns->prefix) + 10) {
if ((size - len > 4) && (buf[len - 1] != '.'))
strcat(buf, " ...");
return;
}
strcat(buf, (char *) cur->ns->prefix);
strcat(buf, ":");
}
if (size - len < xmlStrlen(cur->name) + 10) {
if ((size - len > 4) && (buf[len - 1] != '.'))
strcat(buf, " ...");
return;
}
if (cur->name != NULL)
strcat(buf, (char *) cur->name);
if (cur->next != NULL)
strcat(buf, " ");
break;
}
case XML_TEXT_NODE:
if (xmlIsBlankNode(cur))
break;