[PATCH] memcmp() error in gas/dwarf2dbg.c

Andreas Jaeger aj@suse.de
Fri Feb 13 11:25:00 GMT 2004


Hannes Reinecke <hare@suse.de> writes:

> Hi,
>
> there is a possible memory overflow in gas/dwarf3dbg.c: get_filenum():375
>
> 	if (memcmp (filename, dirs[dir], dir_len) == 0
> 	    && dirs[dir][dir_len] == '\0')
>
> dir_len is set to strlen(filename), which will overflow onto
> unallocated memory if strlen(filename) > strlen(dirs[dir]).
> The attached patch fixes this.
>
> Please keep me cc'ed as I'm not on this list.

If anybody approves it, I'll take care to commit it with a proper
ChangeLog entry after removing the formatting problems in the patch.

> --- binutils-2.14.90.0.8/gas/dwarf2dbg..c.orig	2004-02-13 11:55:05.470239719 +0100
> +++ binutils-2.14.90.0.8/gas/dwarf2dbg.c	2004-02-13 11:57:23.679576129 +0100

Note this patch applies also to current CVS, Hannes noticed it with a
segmentation fault of gas due to accessing beyond the allocated memory.

> @@ -339,7 +339,7 @@ get_filenum (const char *filename, unsig
>  {
>    static unsigned int last_used, last_used_dir_len;
>    const char *file;
> -  size_t dir_len;
> +  size_t dir_len, tmp_len;
>    unsigned int i, dir;
>  
>    if (num == 0 && last_used)
> @@ -372,8 +372,9 @@ get_filenum (const char *filename, unsig
>      {
>        --dir_len;
>        for (dir = 1; dir < dirs_in_use; ++dir)
> -	if (memcmp (filename, dirs[dir], dir_len) == 0
> -	    && dirs[dir][dir_len] == '\0')
> +	tmp_len = strlen(dirs[dir]) < dir_len?strlen(dirs[dir]):dir_len;
> +	if (memcmp (filename, dirs[dir], tmp_len) == 0
> +	    && dirs[dir][tmp_len] == '\0')
>  	  break;
>  
>        if (dir >= dirs_in_use)
 
Andreas
-- 
 Andreas Jaeger, aj@suse.de, http://www.suse.de/~aj
  SuSE Linux AG, Maxfeldstr. 5, 90409 Nürnberg, Germany
   GPG fingerprint = 93A3 365E CE47 B889 DF7F  FED1 389A 563C C272 A126
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 188 bytes
Desc: not available
URL: <https://sourceware.org/pipermail/binutils/attachments/20040213/f8700bd2/attachment.sig>


More information about the Binutils mailing list