• Tomas Vondra's avatar
    Ensure maxlen is at leat 1 in dict_int · b5273943
    Tomas Vondra authored
    The dict_int text search dictionary template accepts maxlen parameter,
    which is then used to cap the length of input strings. The value was
    not properly checked, and the code simply does
    
        txt[d->maxlen] = '\0';
    
    to insert a terminator, leading to segfaults with negative values.
    
    This commit simply rejects values less than 1. The issue was there since
    dct_int was introduced in 9.3, so backpatch all the way back to 9.4
    which is the oldest supported version.
    
    Reported-by: cili
    Discussion: https://postgr.es/m/16144-a36a5bef7657047d@postgresql.org
    Backpatch-through: 9.4
    b5273943
dict_int.out 4.2 KB