]> granicus.if.org Git - curl/commit
unescape: avoid integer overflow
authorDaniel Stenberg <daniel@haxx.se>
Tue, 4 Oct 2016 16:56:45 +0000 (18:56 +0200)
committerDaniel Stenberg <daniel@haxx.se>
Mon, 31 Oct 2016 07:46:35 +0000 (08:46 +0100)
commit53e71e47d6b81650d26ec33a58d0dca24c7ffb2c
treea5f0a1087187b889163113e83f081f8fec9d16d8
parentc5be3d7267c725dbd093ff3a883e07ee8cf2a1d5
unescape: avoid integer overflow

CVE-2016-8622

Bug: https://curl.haxx.se/docs/adv_20161102H.html
Reported-by: Cure53
docs/libcurl/curl_easy_unescape.3
lib/dict.c
lib/escape.c