readelf: Sanity check CIE unit_length and augmentationlen in debug_frame.

Signed-off-by: Mark Wielaard <mjw@redhat.com>
This commit is contained in:
Mark Wielaard
2014-11-14 21:42:47 +01:00
parent df2fe50346
commit d1b1163213
2 changed files with 21 additions and 1 deletions
+5
View File
@@ -1,3 +1,8 @@
2014-11-14 Mark Wielaard <mjw@redhat.com>
* readelf.c (print_debug_frame_section): Sanity Check CIE
unit_length and augmentationlen.
2014-11-14 Mark Wielaard <mjw@redhat.com>
* readelf.c (handle_versym): Check def == NULL before use.
+16 -1
View File
@@ -5332,6 +5332,10 @@ print_debug_frame_section (Dwfl_Module *dwflmod, Ebl *ebl, GElf_Ehdr *ehdr,
continue;
}
Dwarf_Word maxsize = dataend - readp;
if (unlikely (unit_length > maxsize))
goto invalid_data;
unsigned int ptr_size = ehdr->e_ident[EI_CLASS] == ELFCLASS32 ? 4 : 8;
ptrdiff_t start = readp - (unsigned char *) data->d_buf;
@@ -5413,7 +5417,11 @@ print_debug_frame_section (Dwfl_Module *dwflmod, Ebl *ebl, GElf_Ehdr *ehdr,
get_uleb128 (augmentationlen, readp);
if (augmentationlen > (size_t) (dataend - readp))
error (1, 0, gettext ("invalid augmentation length"));
{
error (0, 0, gettext ("invalid augmentation length"));
readp = cieend;
continue;
}
const char *hdr = "Augmentation data:";
const char *cp = augmentation + 1;
@@ -5561,6 +5569,13 @@ print_debug_frame_section (Dwfl_Module *dwflmod, Ebl *ebl, GElf_Ehdr *ehdr,
unsigned int augmentationlen;
get_uleb128 (augmentationlen, readp);
if (augmentationlen > (size_t) (dataend - readp))
{
error (0, 0, gettext ("invalid augmentation length"));
readp = cieend;
continue;
}
if (augmentationlen > 0)
{
const char *hdr = "Augmentation data:";