Fix possible heap corruption in QXmlStream
The value of 'tos' at the check might already be on the last element, so triggering stack expansion on the second last element is too late. Change-Id: Ib3ab2662d4d27a71effe9e988b9e172923af2908 Reviewed-by: Richard J. Moore <rich@kde.org> Reviewed-by: Thiago Macieira <thiago.macieira@intel.com>bb10
parent
6854fa75f7
commit
6256729a6d
|
|
@ -1250,7 +1250,7 @@ bool QXmlStreamReaderPrivate::parse()
|
|||
state_stack[tos] = 0;
|
||||
return true;
|
||||
} else if (act > 0) {
|
||||
if (++tos == stack_size-1)
|
||||
if (++tos >= stack_size-1)
|
||||
reallocateStack();
|
||||
|
||||
Value &val = sym_stack[tos];
|
||||
|
|
|
|||
Loading…
Reference in New Issue