ed96f6
--- ./libcdio-0.92/lib/iso9660/iso9660_fs.c	2018-06-06 11:52:23.464809984 +0200
ed96f6
+++ ../libcdio-fedora/libcdio-0.94/lib/iso9660/iso9660_fs.c	2018-06-05 18:18:31.235215219 +0200
ed96f6
@@ -714,6 +714,7 @@
ed96f6
   iso711_t i_fname;
ed96f6
   unsigned int stat_len;
ed96f6
   iso9660_stat_t *p_stat;
ed96f6
+  bool err;
ed96f6
 
ed96f6
   if (!dir_len) return NULL;
ed96f6
 
ed96f6
@@ -730,8 +731,16 @@
ed96f6
     }
ed96f6
   p_stat->type    = (p_iso9660_dir->file_flags & ISO_DIRECTORY)
ed96f6
     ? _STAT_DIR : _STAT_FILE;
ed96f6
-  p_stat->lsn     = from_733 (p_iso9660_dir->extent);
ed96f6
-  p_stat->size    = from_733 (p_iso9660_dir->size);
ed96f6
+  p_stat->lsn     = from_733_with_err (p_iso9660_dir->extent, &err;;
ed96f6
+  if (err) {
ed96f6
+    free(p_stat);
ed96f6
+    return NULL;
ed96f6
+  }
ed96f6
+  p_stat->size    = from_733_with_err (p_iso9660_dir->size, &err;;
ed96f6
+  if (err) {
ed96f6
+    free(p_stat);
ed96f6
+    return NULL;
ed96f6
+  }
ed96f6
   p_stat->secsize = _cdio_len2blocks (p_stat->size, ISO_BLOCKSIZE);
ed96f6
   p_stat->rr.b3_rock = dunno; /*FIXME should do based on mask */
ed96f6
   p_stat->b_xa    = false;
ed96f6
@@ -754,6 +763,7 @@
ed96f6
         if (!p_stat_new)
ed96f6
           {
ed96f6
           cdio_warn("Couldn't calloc(1, %d)", (int)(sizeof(iso9660_stat_t)+i_rr_fname+2));
ed96f6
+	  free(p_stat);
ed96f6
           return NULL;
ed96f6
           }
ed96f6
 	memcpy(p_stat_new, p_stat, stat_len);
ed96f6
@@ -1098,6 +1108,12 @@
ed96f6
       p_stat = _iso9660_dir_to_statbuf (p_iso9660_dir, p_iso->b_xa,
ed96f6
 					p_iso->u_joliet_level);
ed96f6
 
ed96f6
+      if (!p_stat) {
ed96f6
+	cdio_warn("Bad directory information for %s", splitpath[0]);
ed96f6
+	free(_dirbuf);
ed96f6
+	return NULL;
ed96f6
+      }
ed96f6
+
ed96f6
       cmp = strcmp(splitpath[0], p_stat->filename);
ed96f6
 
ed96f6
       if ( 0 != cmp && 0 == p_iso->u_joliet_level
ed96f6
@@ -1283,12 +1299,15 @@
ed96f6
     if (!_dirbuf)
ed96f6
       {
ed96f6
       cdio_warn("Couldn't calloc(1, %d)", p_stat->secsize * ISO_BLOCKSIZE);
ed96f6
+      _cdio_list_free (retval, true);
ed96f6
       return NULL;
ed96f6
       }
ed96f6
 
ed96f6
     if (cdio_read_data_sectors (p_cdio, _dirbuf, p_stat->lsn,
ed96f6
-				ISO_BLOCKSIZE, p_stat->secsize))
ed96f6
-	return NULL;
ed96f6
+				ISO_BLOCKSIZE, p_stat->secsize)) {
ed96f6
+      _cdio_list_free (retval, true);
ed96f6
+      return NULL;
ed96f6
+    }
ed96f6
 
ed96f6
     while (offset < (p_stat->secsize * ISO_BLOCKSIZE))
ed96f6
       {
ed96f6
@@ -1401,14 +1417,14 @@
ed96f6
       }
ed96f6
 
ed96f6
     free (_dirbuf);
ed96f6
+    free(p_stat->rr.psz_symlink);
ed96f6
 
ed96f6
-    if (offset != (p_stat->secsize * ISO_BLOCKSIZE)) {
ed96f6
-      free (p_stat);
ed96f6
+    if (offset != (p_stat->secsize * ISO_BLOCKSIZE)) {
ed96f6
+      free (p_stat);
ed96f6
       _cdio_list_free (retval, true);
ed96f6
       return NULL;
ed96f6
     }
ed96f6
 
ed96f6
-    free (p_stat->rr.psz_symlink);
ed96f6
     free (p_stat);
ed96f6
     return retval;
ed96f6
   }
ed96f6
@@ -1528,6 +1563,16 @@
ed96f6
 }
ed96f6
 
ed96f6
 /*!
ed96f6
+  Free the passed iso9660_stat_t structure.
ed96f6
+ */
ed96f6
+void
ed96f6
+iso9660_stat_free(iso9660_stat_t *p_stat)
ed96f6
+{
ed96f6
+  if (p_stat != NULL)
ed96f6
+    free(p_stat);
ed96f6
+}
ed96f6
+
ed96f6
+/*!
ed96f6
   Return true if ISO 9660 image has extended attrributes (XA).
ed96f6
 */
ed96f6
 bool
ed96f6
@@ -1580,11 +1625,11 @@
ed96f6
       if ( have_rr != yep) {
ed96f6
 	have_rr = iso_have_rr_traverse (p_iso, p_stat, &splitpath[1], pu_file_limit);
ed96f6
       }
ed96f6
+      free(p_stat);
ed96f6
       if (have_rr != nope) {
ed96f6
 	free (_dirbuf);
ed96f6
 	return have_rr;
ed96f6
       }
ed96f6
-      free(p_stat);
ed96f6
 
ed96f6
       offset += iso9660_get_dir_len(p_iso9660_dir);
ed96f6
       *pu_file_limit = (*pu_file_limit)-1;