summaryrefslogtreecommitdiff
path: root/user/squashfs-tools/CVE-2015-4645.patch
diff options
context:
space:
mode:
authorA. Wilcox <AWilcox@Wilcox-Tech.com>2018-07-05 20:25:27 -0500
committerA. Wilcox <AWilcox@Wilcox-Tech.com>2018-07-05 20:25:27 -0500
commit25dbded13a57b4bae4ba219a5d2874b7035d389e (patch)
tree32498743c47caff20449cc0e894edf1a59ff48f1 /user/squashfs-tools/CVE-2015-4645.patch
parentbe94847a164f9ae0d58332b1de3ed8b037e2fc14 (diff)
downloadpackages-25dbded13a57b4bae4ba219a5d2874b7035d389e.tar.gz
packages-25dbded13a57b4bae4ba219a5d2874b7035d389e.tar.bz2
packages-25dbded13a57b4bae4ba219a5d2874b7035d389e.tar.xz
packages-25dbded13a57b4bae4ba219a5d2874b7035d389e.zip
user/squashfs-tools: pull in, fix, take
Diffstat (limited to 'user/squashfs-tools/CVE-2015-4645.patch')
-rw-r--r--user/squashfs-tools/CVE-2015-4645.patch29
1 files changed, 29 insertions, 0 deletions
diff --git a/user/squashfs-tools/CVE-2015-4645.patch b/user/squashfs-tools/CVE-2015-4645.patch
new file mode 100644
index 000000000..f69025f18
--- /dev/null
+++ b/user/squashfs-tools/CVE-2015-4645.patch
@@ -0,0 +1,29 @@
+diff --git a/squashfs-tools/unsquash-4.c b/squashfs-tools/unsquash-4.c
+index ecdaac796f09..2c0cf63daf67 100644
+--- a/squashfs-tools/unsquash-4.c
++++ b/squashfs-tools/unsquash-4.c
+@@ -31,9 +31,9 @@ static unsigned int *id_table;
+ int read_fragment_table_4(long long *directory_table_end)
+ {
+ int res, i;
+- int bytes = SQUASHFS_FRAGMENT_BYTES(sBlk.s.fragments);
+- int indexes = SQUASHFS_FRAGMENT_INDEXES(sBlk.s.fragments);
+- long long fragment_table_index[indexes];
++ size_t bytes = SQUASHFS_FRAGMENT_BYTES(sBlk.s.fragments);
++ size_t indexes = SQUASHFS_FRAGMENT_INDEXES(sBlk.s.fragments);
++ long long *fragment_table_index;
+
+ TRACE("read_fragment_table: %d fragments, reading %d fragment indexes "
+ "from 0x%llx\n", sBlk.s.fragments, indexes,
+@@ -44,6 +44,11 @@ int read_fragment_table_4(long long *directory_table_end)
+ return TRUE;
+ }
+
++ fragment_table_index = malloc(indexes*sizeof(long long));
++ if(fragment_table_index == NULL)
++ EXIT_UNSQUASH("read_fragment_table: failed to allocate "
++ "fragment table index\n");
++
+ fragment_table = malloc(bytes);
+ if(fragment_table == NULL)
+ EXIT_UNSQUASH("read_fragment_table: failed to allocate "