Title: memory access before short string when checking suffix
Components: Interpreter Core Versions: Python 2.6, Python 2.5
Status: closed Resolution: fixed
Assigned To: doko Nosy List: doko, ralph.corderoy
Created on 2008-09-12 12:11 by doko, last changed 2022-04-11 14:56 by admin.

Messages (2)
msg73083 - (view) Author: Matthias Klose (doko) * (Python committer) Date: 2008-09-12 12:11
forwarded from

Bug reporter writes:

Python/pythonrun.c's PyRun_SimpleFileExFlags() assumes the filename's
starts four characters back from the end. But what if the filename is
only one
character long? Memory before the filename is referenced which is probably
outside the memory allocated for the string. Here's the relevant bits of
boring lines deleted.

    PyRun_SimpleFileExFlags(FILE *fp, const char *filename, int closeit,
                            PyCompilerFlags *flags)
        ext = filename + strlen(filename) - 4;
        if (maybe_pyc_file(fp, filename, ext, closeit)) {
            if (strcmp(ext, ".pyo") == 0)
                Py_OptimizeFlag = 1;

    static int
    maybe_pyc_file(FILE *fp, const char* filename, const char* ext, int
        if (strcmp(ext, ".pyc") == 0 || strcmp(ext, ".pyo") == 0)
            return 1;

A trivial solution is:

    len = strlen(filename);
    ext = filename + len - len > 4 ? 4 : 0;

This will make ext point to the NUL terminator unless filename has room
for the desired /\.py[co]$/ suffix *and* at least one character
beforehand, since I don't suppose it's intended that ".pyo" is a valid
pyo file.
msg85397 - (view) Author: Matthias Klose (doko) * (Python committer) Date: 2009-04-04 14:34
fixed for 2.7, 2.6, 3.1
