From 261897833b475992dea57def8ed18169ade41e83 Mon Sep 17 00:00:00 2001 From: sunpeng Date: Tue, 1 Aug 2023 22:31:37 +0800 Subject: [PATCH] Signed-off-by: SloveZT fix issues #I7OZ6I #I7OZ6H #I7OZ6F and #I7OZ6D for sqlite CVE-2023-36191 --- src/shell.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/src/shell.c b/src/shell.c index dc66c40..4ae82dd 100644 --- a/src/shell.c +++ b/src/shell.c @@ -22527,8 +22527,12 @@ int SQLITE_CDECL wmain(int argc, wchar_t **wargv){ }else if( strcmp(z,"-bail")==0 ){ bail_on_error = 1; }else if( strcmp(z,"-nonce")==0 ){ - free(data.zNonce); - data.zNonce = strdup(argv[++i]); + if( data.zNonce ) free(data.zNonce); + if( i+1 < argc ) data.zNonce = strdup(argv[++i]); + else{ + data.zNonce = 0; + break; + } }else if( strcmp(z,"-safe")==0 ){ /* no-op - catch this on the second pass */ } -- Gitee