Back-patch Neil's four additional buffer overrun checks.

REL7_2_STABLE
Tom Lane 21 years ago
parent ebe0341927
commit 46ace73498
  1. 32
      src/pl/plpgsql/src/gram.y

@ -4,7 +4,7 @@
* procedural language * procedural language
* *
* IDENTIFICATION * IDENTIFICATION
* $Header: /cvsroot/pgsql/src/pl/plpgsql/src/gram.y,v 1.29.2.2 2005/01/27 01:52:34 neilc Exp $ * $Header: /cvsroot/pgsql/src/pl/plpgsql/src/gram.y,v 1.29.2.3 2005/02/08 18:22:54 tgl Exp $
* *
* This software is copyrighted by Jan Wieck - Hamburg. * This software is copyrighted by Jan Wieck - Hamburg.
* *
@ -1565,6 +1565,14 @@ read_sql_construct(int until,
} }
if (plpgsql_SpaceScanned) if (plpgsql_SpaceScanned)
plpgsql_dstring_append(&ds, " "); plpgsql_dstring_append(&ds, " ");
/* Check for array overflow */
if (nparams >= 1024)
{
plpgsql_error_lineno = lno;
elog(ERROR, "too many variables specified in SQL statement");
}
switch (tok) switch (tok)
{ {
case T_VARIABLE: case T_VARIABLE:
@ -1708,6 +1716,14 @@ make_select_stmt()
if (plpgsql_SpaceScanned) if (plpgsql_SpaceScanned)
plpgsql_dstring_append(&ds, " "); plpgsql_dstring_append(&ds, " ");
/* Check for array overflow */
if (nparams >= 1024)
{
plpgsql_error_lineno = yylineno;
elog(ERROR, "too many variables specified in SQL statement");
}
switch (tok) switch (tok)
{ {
case T_VARIABLE: case T_VARIABLE:
@ -1776,6 +1792,13 @@ make_select_stmt()
while ((tok = yylex()) == ',') while ((tok = yylex()) == ',')
{ {
/* Check for array overflow */
if (nfields >= 1024)
{
plpgsql_error_lineno = yylineno;
elog(ERROR, "too many INTO variables specified");
}
tok = yylex(); tok = yylex();
switch(tok) switch(tok)
{ {
@ -1992,6 +2015,13 @@ make_fetch_stmt()
while ((tok = yylex()) == ',') while ((tok = yylex()) == ',')
{ {
/* Check for array overflow */
if (nfields >= 1024)
{
plpgsql_error_lineno = yylineno;
elog(ERROR, "too many INTO variables specified");
}
tok = yylex(); tok = yylex();
switch(tok) switch(tok)
{ {

Loading…
Cancel
Save