Blame SOURCES/file-5.11-CVE-2014-8117.patch

89be67
diff --git a/src/file.h b/src/file.h
89be67
index 28f9bc7..f55d47f 100644
89be67
--- a/src/file.h
89be67
+++ b/src/file.h
89be67
@@ -446,6 +446,14 @@ protected int file_os2_apptype(struct magic_set *, const char *, const void *,
89be67
 #endif /* __EMX__ */
89be67
 
89be67
 
89be67
+typedef struct {
89be67
+	char *buf;
89be67
+	uint32_t offset;
89be67
+} file_pushbuf_t;
89be67
+
89be67
+protected file_pushbuf_t *file_push_buffer(struct magic_set *);
89be67
+protected char  *file_pop_buffer(struct magic_set *, file_pushbuf_t *);
89be67
+
89be67
 #ifndef COMPILE_ONLY
89be67
 extern const char *file_names[];
89be67
 extern const size_t file_nnames;
89be67
diff --git a/src/funcs.c b/src/funcs.c
89be67
index 0d645eb..04bab02 100644
89be67
--- a/src/funcs.c
89be67
+++ b/src/funcs.c
89be67
@@ -459,3 +459,43 @@ file_replace(struct magic_set *ms, const char *pat, const char *rep)
89be67
 		return nm;
89be67
 	}
89be67
 }
89be67
+
89be67
+protected file_pushbuf_t *
89be67
+file_push_buffer(struct magic_set *ms)
89be67
+{
89be67
+	file_pushbuf_t *pb;
89be67
+
89be67
+	if (ms->event_flags & EVENT_HAD_ERR)
89be67
+		return NULL;
89be67
+
89be67
+	if ((pb = (CAST(file_pushbuf_t *, malloc(sizeof(*pb))))) == NULL)
89be67
+		return NULL;
89be67
+
89be67
+	pb->buf = ms->o.buf;
89be67
+	pb->offset = ms->offset;
89be67
+
89be67
+	ms->o.buf = NULL;
89be67
+	ms->offset = 0;
89be67
+
89be67
+	return pb;
89be67
+}
89be67
+
89be67
+protected char *
89be67
+file_pop_buffer(struct magic_set *ms, file_pushbuf_t *pb)
89be67
+{
89be67
+	char *rbuf;
89be67
+
89be67
+	if (ms->event_flags & EVENT_HAD_ERR) {
89be67
+		free(pb->buf);
89be67
+		free(pb);
89be67
+		return NULL;
89be67
+	}
89be67
+
89be67
+	rbuf = ms->o.buf;
89be67
+
89be67
+	ms->o.buf = pb->buf;
89be67
+	ms->offset = pb->offset;
89be67
+
89be67
+	free(pb);
89be67
+	return rbuf;
89be67
+}
89be67
diff --git a/src/softmagic.c b/src/softmagic.c
89be67
index ee979b9..3695add 100644
89be67
--- a/src/softmagic.c
89be67
+++ b/src/softmagic.c
89be67
@@ -60,6 +60,7 @@ private void cvt_32(union VALUETYPE *, const struct magic *);
89be67
 private void cvt_64(union VALUETYPE *, const struct magic *);
89be67
 
89be67
 #define OFFSET_OOB(n, o, i)	((n) < (o) || (i) > ((n) - (o)))
89be67
+
89be67
 /*
89be67
  * softmagic - lookup one file in parsed, in-memory copy of database
89be67
  * Passed the name and FILE * of one file to be typed.
89be67
@@ -1060,6 +1061,9 @@ mget(struct magic_set *ms, const unsigned char *s,
89be67
 {
89be67
 	uint32_t offset = ms->offset;
89be67
 	union VALUETYPE *p = &ms->ms_value;
89be67
+	file_pushbuf_t *pb;
89be67
+	char *rbuf;
89be67
+	int rv;
89be67
 
89be67
 	if (recursion_level >= 20) {
89be67
 		file_error(ms, 0, "recursion nesting exceeded");
89be67
@@ -1620,16 +1624,34 @@ mget(struct magic_set *ms, const unsigned char *s,
89be67
 		break;
89be67
 
89be67
 	case FILE_INDIRECT:
89be67
-	  	if ((ms->flags & (MAGIC_MIME|MAGIC_APPLE)) == 0 &&
89be67
-		    file_printf(ms, "%s", m->desc) == -1)
89be67
-			return -1;
89be67
 		if (offset == 0)
89be67
 			return 0;
89be67
+
89be67
 		if (nbytes < offset)
89be67
- 			return 0;
89be67
-		return file_softmagic(ms, s + offset, nbytes - offset,
89be67
+			return 0;
89be67
+
89be67
+		if ((pb = file_push_buffer(ms)) == NULL)
89be67
+			return -1;
89be67
+
89be67
+		rv = file_softmagic(ms, s + offset, nbytes - offset,
89be67
 		    recursion_level, BINTEST, text);
89be67
 
89be67
+		if ((ms->flags & MAGIC_DEBUG) != 0)
89be67
+			fprintf(stderr, "indirect @offs=%u[%d]\n", offset, rv);
89be67
+
89be67
+		rbuf = file_pop_buffer(ms, pb);
89be67
+		if (rbuf == NULL && ms->event_flags & EVENT_HAD_ERR)
89be67
+			return -1;
89be67
+
89be67
+		if (rv == 1) {
89be67
+			if (file_printf(ms, "%s", rbuf) == -1) {
89be67
+				free(rbuf);
89be67
+				return -1;
89be67
+			}
89be67
+		}
89be67
+		free(rbuf);
89be67
+		return rv;
89be67
+
89be67
 	case FILE_DEFAULT:	/* nothing to check */
89be67
 	default:
89be67
 		break;