mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
naettFree frees the method and url it strdup'd but never the user agent, which stringSetter allocates exactly the same way. We set a user agent on every request, so that leaked on every one of them, on all platforms. On Linux, headerCallback strndup's each header line and only hands it to the header list when it finds a colon - the status line and the blank line that ends the block don't have one, so it leaked those every response, and again per hop when following redirects. defaultBodyWriter grew its capacity by doubling an int until the new data fit. Both the length and the resulting capacity come from the response, so that's signed overflow on a large one, and a negative capacity then reaches realloc as a huge size_t. It also assigned the realloc result straight over the old pointer, so a failed allocation lost the buffer and the memcpy below went through NULL. Grow in int64_t, cap at INT_MAX, and report failure by returning short - which is what every caller already checks for.