blob: cc8d789947318f509e6c021bf95a0813b5420d84 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
|
To: vim-dev@vim.org
Subject: Patch 7.2.297
Fcc: outbox
From: Bram Moolenaar <Bram@moolenaar.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
------------
Patch 7.2.297
Problem: Reading freed memory when writing ":reg" output to a register.
(Dominique Pelle)
Solution: Skip the register being written to.
Files: src/ops.c
*** ../vim-7.2.296/src/ops.c 2009-11-11 17:22:30.000000000 +0100
--- src/ops.c 2009-11-11 19:30:47.000000000 +0100
***************
*** 3991,3996 ****
--- 3991,4004 ----
}
else
yb = &(y_regs[i]);
+
+ #ifdef FEAT_EVAL
+ if (name == MB_TOLOWER(redir_reg)
+ || (redir_reg == '"' && yb == y_previous))
+ continue; /* do not list register being written to, the
+ * pointer can be freed */
+ #endif
+
if (yb->y_array != NULL)
{
msg_putchar('\n');
***************
*** 6090,6096 ****
long maxlen;
#endif
! if (y_ptr->y_array == NULL) /* NULL means emtpy register */
y_ptr->y_size = 0;
/*
--- 6098,6104 ----
long maxlen;
#endif
! if (y_ptr->y_array == NULL) /* NULL means empty register */
y_ptr->y_size = 0;
/*
*** ../vim-7.2.296/src/version.c 2009-11-17 12:31:30.000000000 +0100
--- src/version.c 2009-11-17 12:42:28.000000000 +0100
***************
*** 683,684 ****
--- 683,686 ----
{ /* Add new patch number below this line */
+ /**/
+ 297,
/**/
--
"Beware of bugs in the above code; I have only proved
it correct, not tried it." -- Donald Knuth
/// Bram Moolenaar -- Bram@Moolenaar.net -- http://www.Moolenaar.net \\\
/// sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
\\\ download, build and distribute -- http://www.A-A-P.org ///
\\\ help me help AIDS victims -- http://ICCF-Holland.org ///
|