Public bug reported:

Two more bugs from the same porting effort:

4. XADSkipHandle: broken insertion loop (heap overflow on out-of-order skips)
`XADSkipHandle.m:156-160`

```objc
        for(int i=numregions-1;i>index;i++)
        {
                regions[i+1].actual=regions[i].actual;
                regions[i+1].skip=regions[i].skip-end+start;
        }
```

It is meant to shift regions up to make room for a new skip (the loop
must run *downwards*: `i--`). With `i++` it runs *upwards* instead:
whenever the new skip is not appended after all existing regions (`index
< numregions-1`), the loop keeps writing `regions[i+1]` past the
allocation — a heap buffer overflow — and never performs the intended
shift, corrupting the region table.

**Why it went unnoticed:** all current call sites (ALZip multi-volume,
split-file handling) append skips in increasing offset order, so `index`
always equals the last region and the loop body never executes. The bug
is latent, waiting for the first caller that adds an out-of-order skip.

** Potential fix:** `for(int i=numregions-1;i>index;i--)`.

5. NowCompress: reads uninitialized memory on degenerate headers
`XADNowCompressHandle.m:195-200`

```objc
        if(nextblock>=numblocks)
        {
                if(![self readNextFileHeader]) return 0;
        }

        uint32_t offset=blocks[nextblock].offset;   // may still be out of range
```

`readNextFileHeader` can succeed while leaving `numblocks == 0`
(degenerate header), after which `blocks[nextblock]` reads uninitialized
malloc memory.

**Potential fix:** `if(nextblock>=(int)blocks.size()) return 0;`.

** Affects: unar (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168659

Title:
  Potential memory corruption

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/unar/+bug/2168659/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to