CVE-2014-3479.patch 1.1 KB

1234567891011121314151617181920212223242526272829
  1. commit 36fadd29849b8087af9f4586f89dbf74ea45be67
  2. Author: Christos Zoulas <christos@zoulas.com>
  3. Date: Wed Jun 4 17:26:07 2014 +0000
  4. Use the proper sector size when checking stream offsets (Francisco Alonso and
  5. Jan Kaluza at RedHat)
  6. diff --git a/src/cdf.c b/src/cdf.c
  7. index 6652581..0bfb31a 100644
  8. --- a/src/cdf.c
  9. +++ b/src/cdf.c
  10. @@ -267,13 +267,15 @@ cdf_check_stream_offset(const cdf_stream_t *sst, const cdf_header_t *h,
  11. {
  12. const char *b = (const char *)sst->sst_tab;
  13. const char *e = ((const char *)p) + tail;
  14. + size_t ss = sst->sst_dirlen < h->h_min_size_standard_stream ?
  15. + CDF_SHORT_SEC_SIZE(h) : CDF_SEC_SIZE(h);
  16. (void)&line;
  17. - if (e >= b && (size_t)(e - b) < CDF_SEC_SIZE(h) * sst->sst_len)
  18. + if (e >= b && (size_t)(e - b) <= ss * sst->sst_len)
  19. return 0;
  20. DPRINTF(("%d: offset begin %p end %p %" SIZE_T_FORMAT "u"
  21. " >= %" SIZE_T_FORMAT "u [%" SIZE_T_FORMAT "u %"
  22. SIZE_T_FORMAT "u]\n", line, b, e, (size_t)(e - b),
  23. - CDF_SEC_SIZE(h) * sst->sst_len, CDF_SEC_SIZE(h), sst->sst_len));
  24. + ss * sst->sst_len, ss, sst->sst_len));
  25. errno = EFTYPE;
  26. return -1;
  27. }