Skip to content

Commit

Permalink
patch 9.0.0021: invalid memory access when adding word to spell word …
Browse files Browse the repository at this point in the history
…list

Problem:    Invalid memory access when adding word with a control character to
            the internal spell word list.
Solution:   Disallow adding a word with control characters or a trailing
            slash.
  • Loading branch information
brammool committed Jul 1, 2022
1 parent f12129f commit 5e59ea5
Show file tree
Hide file tree
Showing 3 changed files with 36 additions and 2 deletions.
21 changes: 19 additions & 2 deletions src/spellfile.c
Expand Up @@ -4366,6 +4366,23 @@ wordtree_alloc(spellinfo_T *spin)
return (wordnode_T *)getroom(spin, sizeof(wordnode_T), TRUE);
}

/*
* Return TRUE if "word" contains valid word characters.
* Control characters and trailing '/' are invalid. Space is OK.
*/
static int
valid_spell_word(char_u *word)
{
char_u *p;

if (enc_utf8 && !utf_valid_string(word, NULL))
return FALSE;
for (p = word; *p != NUL; p += mb_ptr2len(p))
if (*p < ' ' || (p[0] == '/' && p[1] == NUL))
return FALSE;
return TRUE;
}

/*
* Store a word in the tree(s).
* Always store it in the case-folded tree. For a keep-case word this is
Expand All @@ -4391,7 +4408,7 @@ store_word(
char_u *p;

// Avoid adding illegal bytes to the word tree.
if (enc_utf8 && !utf_valid_string(word, NULL))
if (!valid_spell_word(word))
return FAIL;

(void)spell_casefold(curwin, word, len, foldword, MAXWLEN);
Expand Down Expand Up @@ -6194,7 +6211,7 @@ spell_add_word(
int i;
char_u *spf;

if (enc_utf8 && !utf_valid_string(word, NULL))
if (!valid_spell_word(word))
{
emsg(_(e_illegal_character_in_word));
return;
Expand Down
15 changes: 15 additions & 0 deletions src/testdir/test_spell.vim
Expand Up @@ -854,6 +854,21 @@ func Test_spellsuggest_too_deep()
bwipe!
endfunc

func Test_spell_good_word_invalid()
" This was adding a word with a 0x02 byte, which causes havoc.
enew
norm o0
sil! norm rzzWs00/
2
sil! norm VzGprzzW
sil! norm z=

bwipe!
" clear the internal word list
set enc=latin1
set enc=utf-8
endfunc

func LoadAffAndDic(aff_contents, dic_contents)
set enc=latin1
set spellfile=
Expand Down
2 changes: 2 additions & 0 deletions src/version.c
Expand Up @@ -735,6 +735,8 @@ static char *(features[]) =

static int included_patches[] =
{ /* Add new patch number below this line */
/**/
21,
/**/
20,
/**/
Expand Down

0 comments on commit 5e59ea5

Please sign in to comment.