From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mga02.intel.com (mga02.intel.com [134.134.136.20]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ml01.01.org (Postfix) with ESMTPS id 5947B21E2BE3E for ; Tue, 19 Sep 2017 07:52:29 -0700 (PDT) Received: from fmsmga003.fm.intel.com ([10.253.24.29]) by orsmga101.jf.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 19 Sep 2017 07:55:34 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.42,418,1500966000"; d="scan'208";a="901858178" Received: from fmsmsx106.amr.corp.intel.com ([10.18.124.204]) by FMSMGA003.fm.intel.com with ESMTP; 19 Sep 2017 07:55:33 -0700 Received: from fmsmsx114.amr.corp.intel.com (10.18.116.8) by FMSMSX106.amr.corp.intel.com (10.18.124.204) with Microsoft SMTP Server (TLS) id 14.3.319.2; Tue, 19 Sep 2017 07:55:33 -0700 Received: from shsmsx104.ccr.corp.intel.com (10.239.4.70) by FMSMSX114.amr.corp.intel.com (10.18.116.8) with Microsoft SMTP Server (TLS) id 14.3.319.2; Tue, 19 Sep 2017 07:55:33 -0700 Received: from shsmsx103.ccr.corp.intel.com ([169.254.4.213]) by SHSMSX104.ccr.corp.intel.com ([169.254.5.152]) with mapi id 14.03.0319.002; Tue, 19 Sep 2017 22:55:31 +0800 From: "Ni, Ruiyu" To: "Wu, Hao A" , "edk2-devel@lists.01.org" CC: "Wu, Hao A" , "Carsey, Jaben" Thread-Topic: [edk2] [PATCH 1/2] ShellPkg/Shell: Avoid reading content beyond string boundary Thread-Index: AQHTMTviYmlh6u82B0W1lYS/szhNDqK8S9ng Date: Tue, 19 Sep 2017 14:55:30 +0000 Deferred-Delivery: Tue, 19 Sep 2017 14:55:00 +0000 Message-ID: <734D49CCEBEEF84792F5B80ED585239D5BA5FB62@SHSMSX103.ccr.corp.intel.com> References: <20170919113833.14048-1-hao.a.wu@intel.com> <20170919113833.14048-2-hao.a.wu@intel.com> In-Reply-To: <20170919113833.14048-2-hao.a.wu@intel.com> Accept-Language: en-US, zh-CN X-MS-Has-Attach: X-MS-TNEF-Correlator: dlp-product: dlpe-windows dlp-version: 11.0.0.116 dlp-reaction: no-action x-originating-ip: [10.239.127.40] MIME-Version: 1.0 Subject: Re: [PATCH 1/2] ShellPkg/Shell: Avoid reading content beyond string boundary X-BeenThere: edk2-devel@lists.01.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: EDK II Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 19 Sep 2017 14:52:29 -0000 Content-Language: en-US Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Reviewed-by: Ruiyu Ni -----Original Message----- From: edk2-devel [mailto:edk2-devel-bounces@lists.01.org] On Behalf Of Hao = Wu Sent: Tuesday, September 19, 2017 7:39 PM To: edk2-devel@lists.01.org Cc: Wu, Hao A ; Ni, Ruiyu ; Carsey,= Jaben Subject: [edk2] [PATCH 1/2] ShellPkg/Shell: Avoid reading content beyond st= ring boundary REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3D690 Within function EfiShellGetDevicePathFromFilePath(), when the input paramet= er 'Path' string is like: "FS0:" It is possible for the below statement: "if (*(Path+StrLen(MapName)+1) =3D=3D CHAR_NULL) {" to read the content 1 byte beyond the string boundary (both 'Path' and 'Map= Name' will be FS0: in this case). This commit adds additional checks to avoid this. Cc: Ruiyu Ni Cc: Jaben Carsey Cc: Steven Shi Contributed-under: TianoCore Contribution Agreement 1.1 Signed-off-by: Hao Wu --- ShellPkg/Application/Shell/ShellProtocol.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/ShellPkg/Application/Shell/ShellProtocol.c b/ShellPkg/Applicat= ion/Shell/ShellProtocol.c index 40e5e653ae..5e34b8dad1 100644 --- a/ShellPkg/Application/Shell/ShellProtocol.c +++ b/ShellPkg/Application/Shell/ShellProtocol.c @@ -598,7 +598,8 @@ EfiShellGetDevicePathFromFilePath( // // build the full device path // - if (*(Path+StrLen(MapName)+1) =3D=3D CHAR_NULL) { + if ((*(Path+StrLen(MapName)) !=3D CHAR_NULL) && + (*(Path+StrLen(MapName)+1) =3D=3D CHAR_NULL)) { DevicePathForReturn =3D FileDevicePath(Handle, L"\\"); } else { DevicePathForReturn =3D FileDevicePath(Handle, Path+StrLen(MapName)); -- 2.12.0.windows.1 _______________________________________________ edk2-devel mailing list edk2-devel@lists.01.org https://lists.01.org/mailman/listinfo/edk2-devel