From 4df03e6ebcf0443429d17027026532336e4b0aca Mon Sep 17 00:00:00 2001 From: infirit Date: Wed, 10 Dec 2014 01:48:23 +0100 Subject: backends: Fix another security issue in the dvi-backend Taken from evince commit: 439c5070022eab6cef7266aab47f978058012c72 From: Vincent Untz Gnome bug: https://bugzilla.gnome.org/show_bug.cgi?id=640923 --- backend/dvi/mdvi-lib/afmparse.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'backend') diff --git a/backend/dvi/mdvi-lib/afmparse.c b/backend/dvi/mdvi-lib/afmparse.c index 361e23d6..e1cd1156 100644 --- a/backend/dvi/mdvi-lib/afmparse.c +++ b/backend/dvi/mdvi-lib/afmparse.c @@ -190,7 +190,7 @@ static char *linetoken(FILE *stream) while ((ch = fgetc(stream)) == ' ' || ch == '\t' ); idx = 0; - while (ch != EOF && ch != lineterm) + while (ch != EOF && ch != lineterm && idx < MAX_NAME) { ident[idx++] = ch; ch = fgetc(stream); -- cgit v1.2.1