diff options
author | Mark Wielaard <mjw@redhat.com> | 2014-12-15 13:40:18 +0100 |
---|---|---|
committer | Mark Wielaard <mjw@redhat.com> | 2014-12-17 16:43:28 +0100 |
commit | 9c42b782ebf32e88d922733b6666ef4b026d760c (patch) | |
tree | 6aa008d8d0c34a4c19c875546598e6f9ab4e0eb8 | |
parent | b171ca4f135f6e4ec894e18aff4d507c1430f86a (diff) | |
download | elfutils-9c42b782ebf32e88d922733b6666ef4b026d760c.tar.gz |
readelf: Make sure there is enough room for reading .debug_line unit_length.
Signed-off-by: Mark Wielaard <mjw@redhat.com>
-rw-r--r-- | src/ChangeLog | 3 | ||||
-rw-r--r-- | src/readelf.c | 2 |
2 files changed, 4 insertions, 1 deletions
diff --git a/src/ChangeLog b/src/ChangeLog index e36bb918..eaf60f0a 100644 --- a/src/ChangeLog +++ b/src/ChangeLog @@ -1,7 +1,8 @@ 2014-12-15 Mark Wielaard <mjw@redhat.com> * readelf.c (print_debug_line_section): Check there is enough room - for DW_LNE_set_address argument. + for DW_LNE_set_address argument. Make sure there is enough room + for the the initial unit_length. 2014-12-14 Mark Wielaard <mjw@redhat.com> diff --git a/src/readelf.c b/src/readelf.c index faaa6d1b..cd8ba869 100644 --- a/src/readelf.c +++ b/src/readelf.c @@ -6333,6 +6333,8 @@ print_debug_line_section (Dwfl_Module *dwflmod, Ebl *ebl, GElf_Ehdr *ehdr, printf (gettext ("\nTable at offset %Zu:\n"), start_offset); + if (unlikely (linep + 4 > lineendp)) + goto invalid_data; Dwarf_Word unit_length = read_4ubyte_unaligned_inc (dbg, linep); unsigned int length = 4; if (unlikely (unit_length == 0xffffffff)) |