fix memory uninitialized in fuzz testcase

Signed-off-by: cherry530 <xuping33@huawei.com>
(cherry picked from commit 58b1cf8b9b35faf706e430d96c85e9e8f1701baa)
This commit is contained in:
cherry530 2022-12-16 17:19:57 +08:00 committed by openeuler-sync-bot
parent 574c658719
commit 1bfbbb8fc2
2 changed files with 18 additions and 1 deletions

View File

@ -0,0 +1,13 @@
diff --git a/sds.c b/sds.c
index 49d2096..9d46dc4 100644
--- a/sds.c
+++ b/sds.c
@@ -513,7 +513,7 @@ sds sdscatvprintf(sds s, const char *fmt, va_list ap) {
} else {
buflen = sizeof(staticbuf);
}
-
+ memset(buf, 0, buflen);
/* Try with buffers two times bigger every time we fail to
* fit the string in the current buffer size. */
while(1) {

View File

@ -1,6 +1,6 @@
Name: hiredis
Version: 1.0.2
Release: 2
Release: 3
Summary: A minimalistic C client library for the Redis database
License: BSD
URL: https://github.com/redis/hiredis
@ -8,6 +8,7 @@ Source0: https://github.com/redis/hiredis/archive/refs/tags/v%{version}.t
BuildRequires: gcc redis
Patch0001: fix-heap-buffer-overflow-in-redisvFormatCommand.patch
Patch0002: fix-memory-uninitialized-in-fuzz-testcase.patch
%description
Hiredis is a minimalistic C client library for the Redis database.
@ -60,6 +61,9 @@ make check || true
%{_libdir}/pkgconfig/hiredis.pc
%changelog
* Fri Dec 16 2022 xu_ping <xuping33@h-partners.com> - 1.0.2-3
- fix memory uninitialized in fuzz testcase
* Tue May 24 2022 loong_C <loong_c@yeah.net> - 1.0.2-2
- fix spec changelog date