From b6ea1b7bbe4e684cc8d87e1d4891a9e88e668667 Mon Sep 17 00:00:00 2001 From: cDc Date: Thu, 19 Mar 2026 06:55:25 +0200 Subject: [PATCH] Fix possible integer overflow in parseString bounds check (#26) * Fix integer overflow in parseString bounds check Cast `base` to `uint64_t` in the parseString bounds check `base+data+num_components <= len` to prevent unsigned integer overflow. When `data` is attacker-controlled (e.g. 0xffffffff), the 32-bit unsigned addition wraps around, causing the check to pass even though the computed offset is far beyond the buffer. This leads to an out-of-bounds heap read or segfault when dereferencing the resulting pointer. Fixes #16 * Fix type casting for base pointer comparison --- TinyEXIF.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/TinyEXIF.cpp b/TinyEXIF.cpp index 3cf1ed8..348257f 100644 --- a/TinyEXIF.cpp +++ b/TinyEXIF.cpp @@ -301,7 +301,7 @@ public: if (value[num_components-1] == '\0') value.resize(num_components-1); } else - if (base+data+num_components <= len) { + if ((uint64_t)base+data+num_components <= (uint64_t)len) { const char* const sz((const char*)buf+base+data); unsigned num(0); while (num < num_components && sz[num] != '\0')