|
|
e5f153 |
From 13f4d47275aca28de7b117359da79f1000e9bcb7 Mon Sep 17 00:00:00 2001
|
|
|
e5f153 |
From: Jakub Martisko <jamartis@redhat.com>
|
|
|
e5f153 |
Date: Wed, 23 May 2018 09:59:18 +0200
|
|
|
e5f153 |
Subject: [PATCH] fix: CVE-2018-7725
|
|
|
e5f153 |
|
|
|
e5f153 |
---
|
|
|
e5f153 |
zzip/memdisk.c | 9 +++++++++
|
|
|
e5f153 |
zzip/mmapped.c | 11 ++++++++++-
|
|
|
e5f153 |
2 files changed, 19 insertions(+), 1 deletion(-)
|
|
|
e5f153 |
|
|
|
e5f153 |
diff --git a/zzip/memdisk.c b/zzip/memdisk.c
|
|
|
e5f153 |
index dc00ea8..043893e 100644
|
|
|
e5f153 |
--- a/zzip/memdisk.c
|
|
|
e5f153 |
+++ b/zzip/memdisk.c
|
|
|
e5f153 |
@@ -413,11 +413,21 @@ zzip_mem_entry_fopen(ZZIP_MEM_DISK * dir, ZZIP_MEM_ENTRY * entry)
|
|
|
e5f153 |
file->zlib.avail_in = zzip_mem_entry_csize(entry);
|
|
|
e5f153 |
file->zlib.next_in = zzip_mem_entry_to_data(entry);
|
|
|
e5f153 |
|
|
|
e5f153 |
+ if (file->zlib.next_in + file->zlib.avail_in >= file->endbuf)
|
|
|
e5f153 |
+ goto error;
|
|
|
e5f153 |
+ if (file->zlib.next_in < file->buffer)
|
|
|
e5f153 |
+ goto error;
|
|
|
e5f153 |
+
|
|
|
e5f153 |
if (! zzip_mem_entry_data_deflated(entry) ||
|
|
|
e5f153 |
inflateInit2(&file->zlib, -MAX_WBITS) != Z_OK)
|
|
|
e5f153 |
{ free (file); return 0; }
|
|
|
e5f153 |
|
|
|
e5f153 |
return file;
|
|
|
e5f153 |
+
|
|
|
e5f153 |
+error:
|
|
|
e5f153 |
+ errno = EBADMSG;
|
|
|
e5f153 |
+ free (file);
|
|
|
e5f153 |
+ return NULL;
|
|
|
e5f153 |
}
|
|
|
e5f153 |
|
|
|
e5f153 |
zzip__new__ ZZIP_MEM_DISK_FILE *
|
|
|
e5f153 |
diff --git a/zzip/mmapped.c b/zzip/mmapped.c
|
|
|
e5f153 |
index 6fafc11..ed3a6cc 100644
|
|
|
e5f153 |
--- a/zzip/mmapped.c
|
|
|
e5f153 |
+++ b/zzip/mmapped.c
|
|
|
e5f153 |
@@ -549,7 +549,12 @@ zzip_disk_entry_fopen(ZZIP_DISK * disk, ZZIP_DISK_ENTRY * entry)
|
|
|
e5f153 |
file->avail = zzip_file_header_usize(header);
|
|
|
e5f153 |
|
|
|
e5f153 |
if (! file->avail || zzip_file_header_data_stored(header))
|
|
|
e5f153 |
- { file->stored = zzip_file_header_to_data (header); return file; }
|
|
|
e5f153 |
+ {
|
|
|
e5f153 |
+ file->stored = zzip_file_header_to_data (header);
|
|
|
e5f153 |
+ if (file->stored + file->avail >= disk->endbuf)
|
|
|
e5f153 |
+ goto error;
|
|
|
e5f153 |
+ return file;
|
|
|
e5f153 |
+ }
|
|
|
e5f153 |
|
|
|
e5f153 |
file->stored = 0;
|
|
|
e5f153 |
file->zlib.opaque = 0;
|
|
|
e5f153 |
@@ -563,6 +568,10 @@ zzip_disk_entry_fopen(ZZIP_DISK * disk, ZZIP_DISK_ENTRY * entry)
|
|
|
e5f153 |
{ free (file); return 0; }
|
|
|
e5f153 |
|
|
|
e5f153 |
return file;
|
|
|
e5f153 |
+error:
|
|
|
e5f153 |
+ free (file);
|
|
|
e5f153 |
+ errno = EBADMSG;
|
|
|
e5f153 |
+ return 0;
|
|
|
e5f153 |
____;
|
|
|
e5f153 |
}
|
|
|
e5f153 |
|
|
|
e5f153 |
--
|
|
|
e5f153 |
2.14.3
|
|
|
e5f153 |
|