aboutsummaryrefslogtreecommitdiff
path: root/http.c
diff options
context:
space:
mode:
authorXavier Del Campo Romero <xavi.dcr@tutanota.com>2023-04-30 22:12:57 +0200
committerXavier Del Campo Romero <xavi.dcr@tutanota.com>2023-05-01 04:13:25 +0200
commit401c5dcf444b50d4fffa66f790aa0ee6a919a967 (patch)
treebeb9d81d41ae55d4a40f4c25de761751cbf12cbe /http.c
parentcfd0a6f7743494f63c6ac5af15bbd3e762591961 (diff)
downloadslcl-401c5dcf444b50d4fffa66f790aa0ee6a919a967.tar.gz
Fix missing error checks for strtoul(3)
Diffstat (limited to 'http.c')
-rw-r--r--http.c10
1 files changed, 9 insertions, 1 deletions
diff --git a/http.c b/http.c
index feb74eb..26c30bf 100644
--- a/http.c
+++ b/http.c
@@ -1897,9 +1897,17 @@ char *http_decode_url(const char *url)
else if (*(url + 1) && *(url + 2))
{
const char buf[sizeof "00"] = {*(url + 1), *(url + 2)};
+ char *endptr;
+ const unsigned long res = strtoul(buf, &endptr, 16);
+
+ if (*endptr)
+ {
+ fprintf(stderr, "%s: invalid number %s\n", __func__, buf);
+ goto failure;
+ }
- ret[n++] = strtoul(buf, NULL, 16);
url += 3;
+ ret[n++] = res;
}
else
{