1
0
Fork 0
mirror of https://github.com/rpm-software-management/popt.git synced 2026-09-20 00:46:06 +00:00
C library for parsing command line parameters
  • C 77%
  • Roff 16.1%
  • Shell 4.2%
  • CMake 2.5%
  • Dockerfile 0.2%
Find a file
Yao Zhang 14c42b415b Fix CVE-2026-18739: off-by-one error in poptStuffArgs()
The poptStuffArgs function only checks whether (con->os - con->optionStack)
is equal to POPT_OPTION_DEPTH (10) before incrementing con->os, and does
not increment the value by 1 to perform boundary pre-checking, as
handleAlias does.

Add a new test program as a reproducer for this case.

Co-authored-by: Panu Matilainen <pmatilai@redhat.com>

Fixes: CVE-2026-18739
2026-08-18 12:28:30 +02:00
.github Add CODEOWNERS to enable automatic review-requests 2024-09-25 11:45:47 +03:00
ci Enable ASAN and UBSAN in the CI build now that we can 2026-08-17 14:44:20 +02:00
cmake cmake: Fix another typo in pkgconfig file template 2023-01-19 20:03:32 -05:00
doc Honor ENABLE_WERROR for Doxygen too 2024-03-04 11:42:51 +02:00
src Fix CVE-2026-18739: off-by-one error in poptStuffArgs() 2026-08-18 12:28:30 +02:00
tests Fix CVE-2026-18739: off-by-one error in poptStuffArgs() 2026-08-18 12:28:30 +02:00
.gitignore Update .gitignore 2020-09-02 12:44:29 +03:00
.popt - jbj: extend coverage to several additional setup routines. 2008-05-05 20:29:45 +00:00
CMakeLists.txt Add options for building with address and undefined behavior sanitizers 2024-03-04 10:48:03 +02:00
COPYING We are not the X Consortium, use straight MIT license text instead 2020-09-02 11:56:08 +03:00
CREDITS Add CREDITS file listing initial main authors and later contributors 2022-01-10 13:34:58 +02:00
popt.3 Fix poptFreeContext() return type in the man page 2024-09-24 14:15:39 +02:00
popt.pdf Convert the documentation PS to PDF and include again in tarballs 2020-05-13 13:09:29 +03:00
README Fix typos 2020-06-26 10:40:34 +03:00

This is the popt(3) command line option parsing library. While it is similar
to getopt(3), it contains a number of enhancements, including:

	1) popt is fully reentrant
	2) popt can parse arbitrary argv[] style arrays while 
	   getopt(3) makes this quite difficult
	3) popt allows users to alias command line arguments
	4) popt provides convenience functions for parsing strings
	   into argv[] style arrays

Complete documentation on popt(3) is available in popt.pdf (included in this
tarball), which is excerpted with permission from the book "Linux
Application Development" by Michael K. Johnson and Erik Troan (available
from Addison Wesley in May, 1998).

Bugs, feature requests and contributions can be submitted at
https://github.com/rpm-software-management/popt or alternatively
rpm-maint@lists.rpm.org.