diff options
| -rw-r--r-- | libbb/process_escape_sequence.c | 12 |
1 files changed, 10 insertions, 2 deletions
diff --git a/libbb/process_escape_sequence.c b/libbb/process_escape_sequence.c index 59d0d3ea8..11adbfcea 100644 --- a/libbb/process_escape_sequence.c +++ b/libbb/process_escape_sequence.c | |||
| @@ -41,8 +41,16 @@ char FAST_FUNC bb_process_escape_sequence(const char **ptr) | |||
| 41 | unsigned d = (unsigned char)(*q) - '0'; | 41 | unsigned d = (unsigned char)(*q) - '0'; |
| 42 | #else | 42 | #else |
| 43 | unsigned d = (unsigned char)_tolower(*q) - '0'; | 43 | unsigned d = (unsigned char)_tolower(*q) - '0'; |
| 44 | if (d >= 10) | 44 | if (d >= 10) { |
| 45 | d += ('0' - 'a' + 10); | 45 | //d += ('0' - 'a' + 10); |
| 46 | /* The above would maps 'A'-'F' and 'a'-'f' to 10-15, | ||
| 47 | * however, some chars like '@' would map to 9 < base. | ||
| 48 | * Do not allow that, map invalid chars to N > base: | ||
| 49 | */ | ||
| 50 | d += ('0' - 'a'); | ||
| 51 | if ((int)d >= 0) | ||
| 52 | d += 10; | ||
| 53 | } | ||
| 46 | #endif | 54 | #endif |
| 47 | if (d >= base) { | 55 | if (d >= base) { |
| 48 | if (WANT_HEX_ESCAPES && base == 16) { | 56 | if (WANT_HEX_ESCAPES && base == 16) { |
