too large: blocksize > 1024*1024*1024 [corrupted]
This commit is contained in:
parent
8939cd120b
commit
330fca722a
@ -3015,7 +3015,7 @@ void PackLinuxElf64::unpack(OutputFile *fo)
|
||||
unsigned orig_file_size = get_te32(&hbuf.p_filesize);
|
||||
blocksize = get_te32(&hbuf.p_blocksize);
|
||||
if (file_size > (off_t)orig_file_size || blocksize > orig_file_size
|
||||
|| (int)(blocksize + OVERHEAD) < 0)
|
||||
|| blocksize > 1024*1024*1024)
|
||||
throwCantUnpack("p_info corrupted");
|
||||
|
||||
ibuf.alloc(blocksize + OVERHEAD);
|
||||
@ -3534,7 +3534,8 @@ void PackLinuxElf32::unpack(OutputFile *fo)
|
||||
p_info hbuf; fi->readx(&hbuf, sizeof(hbuf));
|
||||
unsigned orig_file_size = get_te32(&hbuf.p_filesize);
|
||||
blocksize = get_te32(&hbuf.p_blocksize);
|
||||
if (file_size > (off_t)orig_file_size || blocksize > orig_file_size)
|
||||
if (file_size > (off_t)orig_file_size || blocksize > orig_file_size
|
||||
|| blocksize > 1024*1024*1024)
|
||||
throwCantUnpack("p_info corrupted");
|
||||
|
||||
ibuf.alloc(blocksize + OVERHEAD);
|
||||
|
||||
Loading…
Reference in New Issue
Block a user