Skip to content

Commit 56719e8

Browse files
author
Daniel Balla
committed
Fix multiple JSON.parse issues
Fixes #2180, #2192 JerryScript-DCO-1.0-Signed-off-by: Daniel Balla [email protected]
1 parent 06ebfc5 commit 56719e8

File tree

3 files changed

+37
-2
lines changed

3 files changed

+37
-2
lines changed

jerry-core/ecma/builtin-objects/ecma-builtin-json.c

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -161,6 +161,12 @@ ecma_builtin_json_parse_string (ecma_json_token_t *token_p) /**< token argument
161161
current_p++;
162162
has_escape_sequence = true;
163163

164+
/* If there is an escape sequence but there's no escapable character just return */
165+
if (current_p >= end_p)
166+
{
167+
return;
168+
}
169+
164170
switch (*current_p)
165171
{
166172
case LIT_CHAR_DOUBLE_QUOTE:
@@ -177,8 +183,7 @@ ecma_builtin_json_parse_string (ecma_json_token_t *token_p) /**< token argument
177183
case LIT_CHAR_LOWERCASE_U:
178184
{
179185
ecma_char_t code_unit;
180-
181-
if (!(lit_read_code_unit_from_hex (current_p + 1, 4, &code_unit)))
186+
if ((end_p - current_p >= 2) && !(lit_read_code_unit_from_hex (current_p + 1, 4, &code_unit)))
182187
{
183188
return;
184189
}
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
// Copyright JS Foundation and other contributors, http://js.foundation
2+
//
3+
// Licensed under the Apache License, Version 2.0 (the "License");
4+
// you may not use this file except in compliance with the License.
5+
// You may obtain a copy of the License at
6+
//
7+
// http://www.apache.org/licenses/LICENSE-2.0
8+
//
9+
// Unless required by applicable law or agreed to in writing, software
10+
// distributed under the License is distributed on an "AS IS" BASIS
11+
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12+
// See the License for the specific language governing permissions and
13+
// limitations under the License.
14+
15+
JSON.parse('"' + '\\');
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
// Copyright JS Foundation and other contributors, http://js.foundation
2+
//
3+
// Licensed under the Apache License, Version 2.0 (the "License");
4+
// you may not use this file except in compliance with the License.
5+
// You may obtain a copy of the License at
6+
//
7+
// http://www.apache.org/licenses/LICENSE-2.0
8+
//
9+
// Unless required by applicable law or agreed to in writing, software
10+
// distributed under the License is distributed on an "AS IS" BASIS
11+
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12+
// See the License for the specific language governing permissions and
13+
// limitations under the License.
14+
15+
JSON.parse('"' + '\\u');

0 commit comments

Comments
 (0)