Merge branch 'sb/hex-object-name-is-at-most-41-bytes-long'
[gitweb.git] / hex.c
diff --git a/hex.c b/hex.c
index 9ec5a3b325822e411ac7aa4416d9ea2a53ef94e7..cfd9d722fd92f137a79ee2bf6be44b4b393c6da6 100644 (file)
--- a/hex.c
+++ b/hex.c
@@ -39,7 +39,15 @@ int get_sha1_hex(const char *hex, unsigned char *sha1)
 {
        int i;
        for (i = 0; i < 20; i++) {
-               unsigned int val = (hexval(hex[0]) << 4) | hexval(hex[1]);
+               unsigned int val;
+               /*
+                * hex[1]=='\0' is caught when val is checked below,
+                * but if hex[0] is NUL we have to avoid reading
+                * past the end of the string:
+                */
+               if (!hex[0])
+                       return -1;
+               val = (hexval(hex[0]) << 4) | hexval(hex[1]);
                if (val & ~0xff)
                        return -1;
                *sha1++ = val;