0c48fcbee53684d81c83e92973238ad49d8e1f32 chmalee Wed Sep 23 11:46:28 2026 -0700 Fix the html,css,,javascript, and attribute Encode methods to handle null input strings, refs #38226 diff --git src/lib/htmshell.c src/lib/htmshell.c index cefcb2de0e0..654327dc323 100644 --- src/lib/htmshell.c +++ src/lib/htmshell.c @@ -286,30 +286,36 @@ return cleanQuote; } int htmlEncodeTextExtended(char *s, char *out, int outSize) /* Replaces required punctuation characters with html entities to fight XSS. * out result must be large enough to receive the encoded string. * Returns size of encoded string or -1 if output larger than outSize. * To just get the final encoded size, pass in NULL for out and 0 for outSize. * To output without checking sizes, pass in non-NULL for out and 0 for outSize. */ { int total = 0; char c = 0; +if (s == NULL) + { + if (out) + *out = '\0'; + return 0; + } do { c=*s++; int size = 1; char *newString = NULL; if (c == '&') { size = 5; newString = "&"; } // '&' start a control char if (c == '>') { size = 4; newString = ">" ; } // '>' close of tag if (c == '<') { size = 4; newString = "<" ; } // '<' open of tag if (c == '/') { size = 6; newString = "/"; } // forward slash helps end an HTML entity if (c == '"') { size = 6; newString = """; } // double quote if (c == '\'') { size = 5; newString = "'" ; } // single quote if (out) { if (outSize > 0 && (total+size+1) > outSize) // 1 for terminator { @@ -346,30 +352,36 @@ char *out = needMem(size+1); htmlEncodeTextExtended(s, out, size+1); return out; } int nonAlphaNumericHexEncodeText(char *s, char *out, int outSize, char *prefix, char *postfix) /* For html tag attributes, it replaces non-alphanumeric characters * with <prefix>HH<postfix> hex codes to fight XSS. * out result must be large enough to receive the encoded string. * Returns size of encoded string or -1 if output larger than outSize. * To just get the final encoded size, pass in NULL for out and 0 for outSize. * To output without checking sizes, pass in non-NULL for out and 0 for outSize. */ { +if (s == NULL) + { + if (out) + *out = '\0'; + return 0; + } int encodedSize = strlen(prefix) + 2 + strlen(postfix); int total = 0; char c = 0; do { c=*s++; int size = 1; if (!isalnum(c)) // alpha-numeric { size = encodedSize; } if (c == 0) size = 1; // do not encode the terminating 0 if (out) {