From b8cec255b2cbc9e623c8c4415199a2dbe36f41cf Mon Sep 17 00:00:00 2001 From: "Ryan C. Gordon" Date: Fri, 30 Dec 2011 04:04:34 -0500 Subject: [PATCH] Added some sanity checks to prevent buffer overflows. Fixes Bugzilla #1074. (I think.) --HG-- branch : SDL-1.2 --- src/joystick/linux/SDL_sysjoystick.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/src/joystick/linux/SDL_sysjoystick.c b/src/joystick/linux/SDL_sysjoystick.c index ad717ad16..494439491 100644 --- a/src/joystick/linux/SDL_sysjoystick.c +++ b/src/joystick/linux/SDL_sysjoystick.c @@ -935,6 +935,10 @@ void HandleHat(SDL_Joystick *stick, Uint8 hat, int axis, int value) SDL_logical_joydecl(SDL_Joystick *logicaljoy = NULL); SDL_logical_joydecl(struct joystick_logical_mapping* hats = NULL); + if (stick->nhats <= hat) { + return; /* whoops, that shouldn't happen! */ + } + the_hat = &stick->hwdata->hats[hat]; if ( value < 0 ) { value = 0; @@ -973,6 +977,9 @@ void HandleHat(SDL_Joystick *stick, Uint8 hat, int axis, int value) static __inline__ void HandleBall(SDL_Joystick *stick, Uint8 ball, int axis, int value) { + if ((stick->nballs <= ball) || (axis >= 2)) { + return; /* whoops, that shouldn't happen! */ + } stick->hwdata->balls[ball].axis[axis] += value; }