diff options
author | Doug Zongker <dougz@google.com> | 2014-05-16 15:06:23 +0000 |
---|---|---|
committer | Android Git Automerger <android-git-automerger@android.com> | 2014-05-16 15:06:23 +0000 |
commit | c4804e9b9c143652d17441b4b672b920b11cc94a (patch) | |
tree | 65f33edad5871413e4c6aba9dd129de96cf9ae77 /applypatch | |
parent | 0766cdf49acb77677864995e931eec391243505d (diff) | |
parent | d4592694b41d5f8309d98cd3312b5486216cc685 (diff) | |
download | bootable_recovery-c4804e9b9c143652d17441b4b672b920b11cc94a.zip bootable_recovery-c4804e9b9c143652d17441b4b672b920b11cc94a.tar.gz bootable_recovery-c4804e9b9c143652d17441b4b672b920b11cc94a.tar.bz2 |
am d4592694: am 3ca99f6c: Merge "fix vulnerability in bspatch"
* commit 'd4592694b41d5f8309d98cd3312b5486216cc685':
fix vulnerability in bspatch
Diffstat (limited to 'applypatch')
-rw-r--r-- | applypatch/bspatch.c | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/applypatch/bspatch.c b/applypatch/bspatch.c index 2e80f81..1dc7ab1 100644 --- a/applypatch/bspatch.c +++ b/applypatch/bspatch.c @@ -205,6 +205,11 @@ int ApplyBSDiffPatchMem(const unsigned char* old_data, ssize_t old_size, ctrl[1] = offtin(buf+8); ctrl[2] = offtin(buf+16); + if (ctrl[0] < 0 || ctrl[1] < 0) { + printf("corrupt patch (negative byte counts)\n"); + return 1; + } + // Sanity check if (newpos + ctrl[0] > *new_size) { printf("corrupt patch (new file overrun)\n"); |