From f6c8007a29b95b3ea3ca687a9b4924769a696328 Mon Sep 17 00:00:00 2001 From: Zackery Spytz Date: Mon, 24 Sep 2018 22:25:23 -0600 Subject: [PATCH] bpo-34770: Fix a possible null pointer dereference in pyshellext.cpp (GH-9497) The GlobalLock() call in UpdateDropDescription() was not checked for failure. https://bugs.python.org/issue34770 --- .../next/Windows/2018-09-22-11-02-35.bpo-34770.4lEUOd.rst | 1 + PC/pyshellext.cpp | 5 +++++ 2 files changed, 6 insertions(+) create mode 100644 Misc/NEWS.d/next/Windows/2018-09-22-11-02-35.bpo-34770.4lEUOd.rst diff --git a/Misc/NEWS.d/next/Windows/2018-09-22-11-02-35.bpo-34770.4lEUOd.rst b/Misc/NEWS.d/next/Windows/2018-09-22-11-02-35.bpo-34770.4lEUOd.rst new file mode 100644 index 0000000000..5e4ba8868e --- /dev/null +++ b/Misc/NEWS.d/next/Windows/2018-09-22-11-02-35.bpo-34770.4lEUOd.rst @@ -0,0 +1 @@ +Fix a possible null pointer dereference in pyshellext.cpp. diff --git a/PC/pyshellext.cpp b/PC/pyshellext.cpp index 04fe61e896..019880264b 100644 --- a/PC/pyshellext.cpp +++ b/PC/pyshellext.cpp @@ -172,6 +172,11 @@ private: return E_FAIL; } auto dd = (DROPDESCRIPTION*)GlobalLock(medium.hGlobal); + if (!dd) { + OutputDebugString(L"PyShellExt::UpdateDropDescription - failed to lock DROPDESCRIPTION hGlobal"); + ReleaseStgMedium(&medium); + return E_FAIL; + } StringCchCopy(dd->szMessage, sizeof(dd->szMessage) / sizeof(dd->szMessage[0]), DRAG_MESSAGE); StringCchCopy(dd->szInsert, sizeof(dd->szInsert) / sizeof(dd->szInsert[0]), PathFindFileNameW(target)); dd->type = DROPIMAGE_MOVE; -- 2.49.0