diff options
author | Lucio Andrés Illanes Albornoz (arab, vxp) <lucio@lucioillanes.de> | 2018-05-05 17:00:46 +0000 |
---|---|---|
committer | Lucio Andrés Illanes Albornoz (arab, vxp) <lucio@lucioillanes.de> | 2018-05-05 17:00:46 +0000 |
commit | f4185f01cbd9d5cfaf69eac5d87e247a7746f6c0 (patch) | |
tree | d24215488fad25a825a5b402bd2ee821d6ab8fc9 | |
parent | f1617775b815e0737e59e5361254250c4b43f3ad (diff) | |
download | midipix_build-f4185f01cbd9d5cfaf69eac5d87e247a7746f6c0.tar.bz2 midipix_build-f4185f01cbd9d5cfaf69eac5d87e247a7746f6c0.tar.xz |
patches/libarchive-3.3.2.local.patch: merges CVE-2017-14166.patch from [1] (via Redfoxmon.)
References:
Sat, 05 May 2018 17:01:11 +0000 [1] <https://git.alpinelinux.org/cgit/aports/tree/main/libarchive/CVE-2017-14166.patch>
-rw-r--r-- | patches/libarchive-3.3.2.local.patch | 36 |
1 files changed, 36 insertions, 0 deletions
diff --git a/patches/libarchive-3.3.2.local.patch b/patches/libarchive-3.3.2.local.patch index 5ab5610a..7bf80662 100644 --- a/patches/libarchive-3.3.2.local.patch +++ b/patches/libarchive-3.3.2.local.patch @@ -10,3 +10,39 @@ #include <stdlib.h> /* malloc, free */ #include <string.h> /* memset */ static inline HMAC_CTX *HMAC_CTX_new(void) +From fa7438a0ff4033e4741c807394a9af6207940d71 Mon Sep 17 00:00:00 2001 +From: Joerg Sonnenberger <joerg@bec.de> +Date: Tue, 5 Sep 2017 18:12:19 +0200 +Subject: [PATCH] Do something sensible for empty strings to make fuzzers + happy. + +--- + libarchive/archive_read_support_format_xar.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/libarchive/archive_read_support_format_xar.c b/libarchive/archive_read_support_format_xar.c +index 7a22beb9d..93eeacc5e 100644 +--- a/libarchive/archive_read_support_format_xar.c ++++ b/libarchive/archive_read_support_format_xar.c +@@ -1040,6 +1040,9 @@ atol10(const char *p, size_t char_cnt) + uint64_t l; + int digit; + ++ if (char_cnt == 0) ++ return (0); ++ + l = 0; + digit = *p - '0'; + while (digit >= 0 && digit < 10 && char_cnt-- > 0) { +@@ -1054,7 +1057,10 @@ atol8(const char *p, size_t char_cnt) + { + int64_t l; + int digit; +- ++ ++ if (char_cnt == 0) ++ return (0); ++ + l = 0; + while (char_cnt-- > 0) { + if (*p >= '0' && *p <= '7') |