From: Bram Moolenaar Date: Tue, 13 Mar 2018 12:10:41 +0000 (+0100) Subject: patch 8.0.1602: crash in parsing JSON X-Git-Tag: v8.0.1602 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=625f0c1eb75da08229843fa393b1ee4e6547d285;p=vim patch 8.0.1602: crash in parsing JSON Problem: Crash in parsing JSON. Solution: Fail when using array or dict as dict key. (Damien) --- diff --git a/src/json.c b/src/json.c index 6f914ea03..e1f40bf65 100644 --- a/src/json.c +++ b/src/json.c @@ -621,7 +621,9 @@ json_decode_item(js_read_T *reader, typval_T *res, int options) if (top_item != NULL && top_item->jd_type == JSON_OBJECT_KEY && (options & JSON_JS) && reader->js_buf[reader->js_used] != '"' - && reader->js_buf[reader->js_used] != '\'') + && reader->js_buf[reader->js_used] != '\'' + && reader->js_buf[reader->js_used] != '[' + && reader->js_buf[reader->js_used] != '{') { char_u *key; @@ -642,6 +644,11 @@ json_decode_item(js_read_T *reader, typval_T *res, int options) switch (*p) { case '[': /* start of array */ + if (top_item && top_item->jd_type == JSON_OBJECT_KEY) + { + retval = FAIL; + break; + } if (ga_grow(&stack, 1) == FAIL) { retval = FAIL; @@ -668,6 +675,11 @@ json_decode_item(js_read_T *reader, typval_T *res, int options) continue; case '{': /* start of object */ + if (top_item && top_item->jd_type == JSON_OBJECT_KEY) + { + retval = FAIL; + break; + } if (ga_grow(&stack, 1) == FAIL) { retval = FAIL; diff --git a/src/testdir/test_json.vim b/src/testdir/test_json.vim index acd2ea85b..396651e6b 100644 --- a/src/testdir/test_json.vim +++ b/src/testdir/test_json.vim @@ -179,6 +179,9 @@ func Test_json_decode() call assert_fails('call json_decode("[1 2]")', "E474:") call assert_fails('call json_decode("[1,,2]")', "E474:") + + call assert_fails('call json_decode("{{}:42}")', "E474:") + call assert_fails('call json_decode("{[]:42}")', "E474:") endfunc let s:jsl5 = '[7,,,]' diff --git a/src/version.c b/src/version.c index 50422aada..2a537e6b1 100644 --- a/src/version.c +++ b/src/version.c @@ -766,6 +766,8 @@ static char *(features[]) = static int included_patches[] = { /* Add new patch number below this line */ +/**/ + 1602, /**/ 1601, /**/