patch 9.1.0006: is*() and to*() function may be unsafe
Problem:  is*() and to*() function may be unsafe
Solution: Add SAFE_* macros and start using those instead
          (Keith Thompson)
Use SAFE_() macros for is*() and to*() functions
The standard is*() and to*() functions declared in <ctype.h> have
undefined behavior for negative arguments other than EOF.  If plain char
is signed, passing an unchecked value from argv for from user input
to one of these functions has undefined behavior.
Solution: Add SAFE_*() macros that cast the argument to unsigned char.
Most implementations behave sanely for negative arguments, and most
character values in practice are non-negative, but it's still best
to avoid undefined behavior.
The change from #13347 has been omitted, as this has already been
separately fixed in commit ac709e2fc0
(v9.0.2054)
fixes: #13332
closes: #13347
Signed-off-by: Keith Thompson <Keith.S.Thompson@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
			
			
This commit is contained in:
		
				
					committed by
					
						 Christian Brabandt
						Christian Brabandt
					
				
			
			
				
	
			
			
			
						parent
						
							4d8cb683b1
						
					
				
				
					commit
					184f71cc68
				
			| @ -2760,7 +2760,7 @@ main(int argc, char **argv) | ||||
| 	    rewind(stdin); | ||||
| 	    if (scanf("%99s", buf) == 1) | ||||
| 	    { | ||||
| 		if (isdigit(buf[0])) | ||||
| 		if (isdigit((unsigned char)buf[0])) | ||||
| 		{ | ||||
| 		    // Change a choice. | ||||
| 		    i = atoi(buf); | ||||
|  | ||||
		Reference in New Issue
	
	Block a user