[PATCH 1/4] Decompressors: Fix header validation in decompress_unlzma.c

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Lasse Collin
Date: Tuesday, November 23, 2010 - 3:15 am

From: Lasse Collin <lasse.collin@tukaani.org>

Validation of header.pos calls error() but doesn't make the
function return to indicate an error to the caller. Instead
the decoding is attempted with invalid header.pos. This
fixes it.

Signed-off-by: Lasse Collin <lasse.collin@tukaani.org>
---

--- linux-2.6.37-rc3/lib/decompress_unlzma.c.orig	2010-10-20 23:30:22.000000000 +0300
+++ linux-2.6.37-rc3/lib/decompress_unlzma.c	2010-11-23 11:07:28.000000000 +0200
@@ -580,8 +580,10 @@ STATIC inline int INIT unlzma(unsigned c
 		((unsigned char *)&header)[i] = *rc.ptr++;
 	}
 
-	if (header.pos >= (9 * 5 * 5))
+	if (header.pos >= (9 * 5 * 5)) {
 		error("bad header");
+		goto exit_1;
+	}
 
 	mi = 0;
 	lc = header.pos;
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 1/4] Decompressors: Fix header validation in decomp ..., Lasse Collin, (Tue Nov 23, 3:15 am)