Lucene: limit and offset are summed together without validation which can cause an integer overflow
Bug #728325 reported by
Vesa Marttila
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Querydsl |
Fix Released
|
Low
|
Vesa Marttila |
Bug Description
The negative value is then passed to Lucene which throws a NegativeArraySi
Changed in querydsl: | |
assignee: | nobody → Vesa Marttila (ponzao) |
importance: | Undecided → Low |
To post a comment you must log in.
Fixed by throwing a QueryException if the sum of limit and offset is negative.