Sat, 18 Sep 2004 23:17:18 +0000
[gaim-migrate @ 10998]
A patch from rian hunter (chrono86):
In src/protocols/oscar/oscar.c, in the function
gaim_plugin_oscar_convert_to_best_encoding. g_convert
is called multiple times. As its 5th argument g_convert
takes a gsize* (8 byte), yet the argument to
gaim_plugin_oscar_convert_to_best_encoding is a int* (4
byte).
On LP64 machines this can allow the int* to be
overwritten. This is especially bad on big endian
64-bit machines, causing the high 32-bits to be written
into the low 32-bits of the int.
This is a quick fix patch that lets g_convert deal with
a gsize* pointer instead, then casting the value at
gsize* to the value at the int*.
A real fix would be to fix the aim_sendimext_args
structure to have a gsize instead of an int (and all
functions that use the aim_sendimext_args struct), and
changing gaim_plugin_oscar_convert_to_best_encoding to
accept a gsize*. of course, this woudl promote glib2
dependence, so that's probably not the best thing to do.
committer: Mark Doliner <markdoliner@pidgin.im>
| 2672 | 1 | /* |
|
3952
d13e1fde68d8
[gaim-migrate @ 4133]
Mark Doliner <markdoliner@pidgin.im>
parents:
2672
diff
changeset
|
2 | * Family 0x000c - Translation. |
|
d13e1fde68d8
[gaim-migrate @ 4133]
Mark Doliner <markdoliner@pidgin.im>
parents:
2672
diff
changeset
|
3 | * |
| 2672 | 4 | * I have no idea why this group was issued. I have never seen anything |
| 5 | * that uses it. From what I remember, the last time I tried to poke at | |
| 6 | * the server with this group, it whined about not supporting it. | |
| 7 | * | |
| 8 | * But we advertise it anyway, because its fun. | |
| 9 | * | |
| 10 | */ | |
| 11 | ||
| 12 | #define FAIM_INTERNAL | |
| 13 | #include <aim.h> | |
| 14 | ||
| 15 | faim_internal int translate_modfirst(aim_session_t *sess, aim_module_t *mod) | |
| 16 | { | |
| 17 | ||
| 18 | mod->family = 0x000c; | |
| 19 | mod->version = 0x0001; | |
| 20 | mod->toolid = 0x0104; | |
| 21 | mod->toolversion = 0x0001; | |
| 22 | mod->flags = 0; | |
| 23 | strncpy(mod->name, "translate", sizeof(mod->name)); | |
| 24 | mod->snachandler = NULL; | |
| 25 | ||
| 26 | return 0; | |
| 27 | } |