From 12dcad5b1ec58eb33c351854ae37942b996ed2e5 Mon Sep 17 00:00:00 2001 From: "Gao, Zhichao" Date: Mon, 12 Aug 2019 08:36:21 -0700 Subject: ShellPkg/UefiShellLevel2CommansLib: Pointer Resonse should be checked REF: https://bugzilla.tianocore.org/show_bug.cgi?id=2049 ShellPkg\Library\UefiShellLevel2CommandsLib\Cp.c line 104 and ShellPkg\Library\UefiShellLevel2CommandsLib\Mv.c line 640, the pointer variable Response may be a NULL pointer. So we should make sure that it isn't NULL before dereference it. If Response is NULL that indicates a EFI_OUT_OF_RESOURCES error, directly return SHELL_ABORTED. Cc: Jaben Carsey Cc: Ray Ni Signed-off-by: Zhichao Gao Reviewed-by: Jaben Carsey --- ShellPkg/Library/UefiShellLevel2CommandsLib/Cp.c | 5 ++++- ShellPkg/Library/UefiShellLevel2CommandsLib/Mv.c | 5 ++++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/ShellPkg/Library/UefiShellLevel2CommandsLib/Cp.c b/ShellPkg/Library/UefiShellLevel2CommandsLib/Cp.c index 18b05b5803..4a2c2cfe64 100644 --- a/ShellPkg/Library/UefiShellLevel2CommandsLib/Cp.c +++ b/ShellPkg/Library/UefiShellLevel2CommandsLib/Cp.c @@ -2,7 +2,7 @@ Main file for cp shell level 2 function. (C) Copyright 2015 Hewlett-Packard Development Company, L.P.
- Copyright (c) 2009 - 2018, Intel Corporation. All rights reserved.
+ Copyright (c) 2009 - 2019, Intel Corporation. All rights reserved.
SPDX-License-Identifier: BSD-2-Clause-Patent **/ @@ -101,6 +101,9 @@ CopySingleFile( // possibly return based on response // if (!SilentMode) { + if (Response == NULL) { + return SHELL_ABORTED; + } switch (*(SHELL_PROMPT_RESPONSE*)Response) { case ShellPromptResponseNo: // diff --git a/ShellPkg/Library/UefiShellLevel2CommandsLib/Mv.c b/ShellPkg/Library/UefiShellLevel2CommandsLib/Mv.c index 8c2852d7eb..f50c1e4c20 100644 --- a/ShellPkg/Library/UefiShellLevel2CommandsLib/Mv.c +++ b/ShellPkg/Library/UefiShellLevel2CommandsLib/Mv.c @@ -2,7 +2,7 @@ Main file for mv shell level 2 function. (C) Copyright 2013-2015 Hewlett-Packard Development Company, L.P.
- Copyright (c) 2009 - 2018, Intel Corporation. All rights reserved.
+ Copyright (c) 2009 - 2019, Intel Corporation. All rights reserved.
SPDX-License-Identifier: BSD-2-Clause-Patent **/ @@ -637,6 +637,9 @@ ValidateAndMoveFiles( if (Response == NULL) { ShellPromptForResponseHii(ShellPromptResponseTypeYesNoAllCancel, STRING_TOKEN (STR_GEN_DEST_EXIST_OVR), gShellLevel2HiiHandle, &Response); } + if (Response == NULL) { + return SHELL_ABORTED; + } switch (*(SHELL_PROMPT_RESPONSE*)Response) { case ShellPromptResponseNo: FreePool(Response); -- cgit v1.2.3