32a5a4
From 81da2f651b65dbd2f387625d304ab14ed8b2ca29 Mon Sep 17 00:00:00 2001
32a5a4
From: Jakub Martisko <jamartis@redhat.com>
32a5a4
Date: Thu, 14 Jun 2018 09:19:41 +0200
32a5a4
Subject: [PATCH] fix: CVE-2018-7727
32a5a4
32a5a4
---
32a5a4
 bins/unzip-mem.c     | 2 +-
32a5a4
 bins/unzzipcat-mem.c | 7 +++----
32a5a4
 bins/unzzipdir-mem.c | 8 ++++----
32a5a4
 3 files changed, 8 insertions(+), 9 deletions(-)
32a5a4
32a5a4
diff --git a/bins/unzip-mem.c b/bins/unzip-mem.c
32a5a4
index 3f7d7f0..0b28b9b 100644
32a5a4
--- a/bins/unzip-mem.c
32a5a4
+++ b/bins/unzip-mem.c
32a5a4
@@ -409,7 +409,7 @@ main (int argc, char ** argv)
32a5a4
 	    }
32a5a4
 	}
32a5a4
     }
32a5a4
-
32a5a4
+    zzip_mem_disk_close(disk);
32a5a4
     return status;
32a5a4
 } 
32a5a4
 
32a5a4
diff --git a/bins/unzzipcat-mem.c b/bins/unzzipcat-mem.c
32a5a4
index 7474854..6f16989 100644
32a5a4
--- a/bins/unzzipcat-mem.c
32a5a4
+++ b/bins/unzzipcat-mem.c
32a5a4
@@ -93,10 +93,9 @@ main (int argc, char ** argv)
32a5a4
 	    char* name = zzip_mem_entry_to_name (entry);
32a5a4
 	    printf ("%s\n", name);
32a5a4
 	}
32a5a4
-	return 0;
32a5a4
     }
32a5a4
 
32a5a4
-    if (argc == 3)
32a5a4
+    else if (argc == 3)
32a5a4
     {  /* list from one spec */
32a5a4
 	ZZIP_MEM_ENTRY* entry = 0;
32a5a4
 	while ((entry = zzip_mem_disk_findmatch(disk, argv[2], entry, 0, 0)))
32a5a4
@@ -104,10 +103,9 @@ main (int argc, char ** argv)
32a5a4
 	     zzip_mem_entry_fprint (disk, entry, stdout);
32a5a4
 	}
32a5a4
 
32a5a4
-	return 0;
32a5a4
     }
32a5a4
 
32a5a4
-    for (argn=1; argn < argc; argn++)
32a5a4
+    else for (argn=1; argn < argc; argn++)
32a5a4
     {   /* list only the matching entries - each in order of commandline */
32a5a4
 	ZZIP_MEM_ENTRY* entry = zzip_mem_disk_findfirst(disk);
32a5a4
 	for (; entry ; entry = zzip_mem_disk_findnext(disk, entry))
32a5a4
@@ -118,6 +116,7 @@ main (int argc, char ** argv)
32a5a4
 		zzip_mem_disk_cat_file (disk, name, stdout);
32a5a4
 	}
32a5a4
     }
32a5a4
+    zzip_mem_disk_close(disk);
32a5a4
     return 0;
32a5a4
 } 
32a5a4
 
32a5a4
diff --git a/bins/unzzipdir-mem.c b/bins/unzzipdir-mem.c
32a5a4
index dc02077..9ebdb6d 100644
32a5a4
--- a/bins/unzzipdir-mem.c
32a5a4
+++ b/bins/unzzipdir-mem.c
32a5a4
@@ -64,10 +64,9 @@ main (int argc, char ** argv)
32a5a4
 	    char* name = zzip_mem_entry_to_name (entry);
32a5a4
 	    printf ("%s\n", name);
32a5a4
 	}
32a5a4
-	return 0;
32a5a4
     }
32a5a4
 
32a5a4
-    if (argc == 3)
32a5a4
+    else if (argc == 3)
32a5a4
     {  /* list from one spec */
32a5a4
 	ZZIP_MEM_ENTRY* entry = 0;
32a5a4
 	while ((entry = zzip_mem_disk_findmatch(disk, argv[2], entry, 0, 0)))
32a5a4
@@ -75,9 +74,9 @@ main (int argc, char ** argv)
32a5a4
 	    char* name = zzip_mem_entry_to_name (entry);
32a5a4
 	    printf ("%s\n", name);
32a5a4
 	}
32a5a4
-	return 0;
32a5a4
     }
32a5a4
 
32a5a4
+    else
32a5a4
     {   /* list only the matching entries - in order of zip directory */
32a5a4
 	ZZIP_MEM_ENTRY* entry = zzip_mem_disk_findfirst(disk);
32a5a4
 	for (; entry ; entry = zzip_mem_disk_findnext(disk, entry))
32a5a4
@@ -90,8 +89,9 @@ main (int argc, char ** argv)
32a5a4
 		    printf ("%s\n", name);
32a5a4
 	    }
32a5a4
 	}
32a5a4
-	return 0;
32a5a4
     }
32a5a4
+    zzip_mem_disk_close(disk);
32a5a4
+    return 0;
32a5a4
 } 
32a5a4
 
32a5a4
 /* 
32a5a4
-- 
32a5a4
2.14.4
32a5a4