From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.bugs Subject: bug#29523: 25.3; buffer overflow in ns-font-name on mac Date: Sat, 02 Dec 2017 10:10:09 +0200 Message-ID: <83r2sd1rfi.fsf@gnu.org> References: <20171201.235334.2302300328404793169.masm@luna.pink.masm11.ddo.jp> <20171201194308.GA44478@breton.holly.idiocy.org> Reply-To: Eli Zaretskii NNTP-Posting-Host: blaine.gmane.org X-Trace: blaine.gmane.org 1512202279 11212 195.159.176.226 (2 Dec 2017 08:11:19 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Sat, 2 Dec 2017 08:11:19 +0000 (UTC) Cc: 29523@debbugs.gnu.org, masm-emacs@masm11.ddo.jp To: Alan Third Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Sat Dec 02 09:11:15 2017 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1eL2tG-0002ad-GH for geb-bug-gnu-emacs@m.gmane.org; Sat, 02 Dec 2017 09:11:14 +0100 Original-Received: from localhost ([::1]:34719 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eL2tM-00084F-22 for geb-bug-gnu-emacs@m.gmane.org; Sat, 02 Dec 2017 03:11:20 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:37888) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eL2tA-000847-2k for bug-gnu-emacs@gnu.org; Sat, 02 Dec 2017 03:11:08 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eL2t5-0001jv-EE for bug-gnu-emacs@gnu.org; Sat, 02 Dec 2017 03:11:08 -0500 Original-Received: from debbugs.gnu.org ([208.118.235.43]:60500) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1eL2t5-0001jk-Ah for bug-gnu-emacs@gnu.org; Sat, 02 Dec 2017 03:11:03 -0500 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1eL2t4-0006zs-Um for bug-gnu-emacs@gnu.org; Sat, 02 Dec 2017 03:11:03 -0500 X-Loop: help-debbugs@gnu.org Resent-From: Eli Zaretskii Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Sat, 02 Dec 2017 08:11:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 29523 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Original-Received: via spool by 29523-submit@debbugs.gnu.org id=B29523.151220224226867 (code B ref 29523); Sat, 02 Dec 2017 08:11:02 +0000 Original-Received: (at 29523) by debbugs.gnu.org; 2 Dec 2017 08:10:42 +0000 Original-Received: from localhost ([127.0.0.1]:40948 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1eL2sj-0006zH-Me for submit@debbugs.gnu.org; Sat, 02 Dec 2017 03:10:41 -0500 Original-Received: from eggs.gnu.org ([208.118.235.92]:46713) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1eL2sg-0006yy-0j for 29523@debbugs.gnu.org; Sat, 02 Dec 2017 03:10:39 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eL2sV-0001ND-Ps for 29523@debbugs.gnu.org; Sat, 02 Dec 2017 03:10:32 -0500 Original-Received: from fencepost.gnu.org ([2001:4830:134:3::e]:44404) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eL2sV-0001N1-MK; Sat, 02 Dec 2017 03:10:27 -0500 Original-Received: from [176.228.60.248] (port=3846 helo=home-c4e4a596f7) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1eL2sV-0008Kf-5r; Sat, 02 Dec 2017 03:10:27 -0500 In-reply-to: <20171201194308.GA44478@breton.holly.idiocy.org> (message from Alan Third on Fri, 1 Dec 2017 19:43:08 +0000) X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:140615 Archived-At: > Date: Fri, 1 Dec 2017 19:43:08 +0000 > From: Alan Third > Cc: 29523@debbugs.gnu.org > > > The bug is in ns_xlfd_to_fontname() in nsterm.m: > > > > if (!strncmp (xlfd, "--", 2)) > > sscanf (xlfd, "--%*[^-]-%[^-]179-", name); > > else > > sscanf (xlfd, "-%*[^-]-%[^-]179-", name); > > > > The positions of "179" are incorrect. They should be: > > > > if (!strncmp (xlfd, "--", 2)) > > sscanf (xlfd, "--%*[^-]-%179[^-]-", name); > > else > > sscanf (xlfd, "-%*[^-]-%179[^-]-", name); > > Thanks for the fix. I expect this is copyright exempt It is. Thanks.