diff --git a/libgfortran/ChangeLog b/libgfortran/ChangeLog index 0db6850733c..b4f77b77e21 100644 --- a/libgfortran/ChangeLog +++ b/libgfortran/ChangeLog @@ -1,3 +1,8 @@ +2007-12-25 Jerry DeLisle + + * io/transfer.c (read_sf): Check if readlen was less than the requested + number of bytes to read and if so, generate error. + 2007-12-25 Daniel Franke PR fortran/34533 diff --git a/libgfortran/io/transfer.c b/libgfortran/io/transfer.c index 5dddcd31481..48f6033465f 100644 --- a/libgfortran/io/transfer.c +++ b/libgfortran/io/transfer.c @@ -166,7 +166,14 @@ read_sf (st_parameter_dt *dtp, int *length, int no_error) { readlen = *length; q = salloc_r (dtp->u.p.current_unit->s, &readlen); - memcpy (p, q, readlen); + if (readlen < *length) + { + generate_error (&dtp->common, LIBERROR_END, NULL); + return NULL; + } + + if (q != NULL) + memcpy (p, q, readlen); goto done; }