From 7ee3dcb3c603b20fcd4547ffb00e11701c6d1cf4 Mon Sep 17 00:00:00 2001 From: Rich Felker Date: Sun, 4 Sep 2011 10:29:04 -0400 Subject: memstreams: fix incorrect handling of file pos > current size the addition is safe and cannot overflow because both operands are positive when considered as signed quantities. --- src/stdio/open_memstream.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'src/stdio/open_memstream.c') diff --git a/src/stdio/open_memstream.c b/src/stdio/open_memstream.c index 7fc16204..687e818d 100644 --- a/src/stdio/open_memstream.c +++ b/src/stdio/open_memstream.c @@ -32,8 +32,8 @@ static size_t ms_write(FILE *f, const unsigned char *buf, size_t len) f->wpos = f->wbase; if (ms_write(f, f->wbase, len2) < len2) return 0; } - if (len >= c->space - c->pos) { - len2 = 2*c->space+1 | c->space+len+1; + if (len + c->pos >= c->space) { + len2 = 2*c->space+1 | c->pos+len+1; newbuf = realloc(c->buf, len2); if (!newbuf) return 0; *c->bufp = c->buf = newbuf; -- cgit v1.2.1