aboutsummaryrefslogtreecommitdiff
path: root/bfd/elf.c
diff options
context:
space:
mode:
authorNick Clifton <nickc@redhat.com>2018-05-08 12:51:06 +0100
committerNick Clifton <nickc@redhat.com>2018-05-08 12:51:06 +0100
commit95a6d23566165208853a68d9cd3c6eedca840ec6 (patch)
tree18cb44eee880d8c8d20b2cd2117f961603d585f1 /bfd/elf.c
parenta87a64780fde9dc8d1c3af8eda93fc1b878cd3cf (diff)
downloadbinutils-95a6d23566165208853a68d9cd3c6eedca840ec6.zip
binutils-95a6d23566165208853a68d9cd3c6eedca840ec6.tar.gz
binutils-95a6d23566165208853a68d9cd3c6eedca840ec6.tar.bz2
Prevent a memory exhaustion failure when running objdump on a fuzzed input file with corrupt string and attribute sections.
PR 22809 * elf.c (bfd_elf_get_str_section): Check for an excessively large string section. * elf-attrs.c (_bfd_elf_parse_attributes): Issue an error if the attribute section is larger than the size of the file.
Diffstat (limited to 'bfd/elf.c')
-rw-r--r--bfd/elf.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/bfd/elf.c b/bfd/elf.c
index 21bc4e7..3e8d510 100644
--- a/bfd/elf.c
+++ b/bfd/elf.c
@@ -298,6 +298,7 @@ bfd_elf_get_str_section (bfd *abfd, unsigned int shindex)
/* Allocate and clear an extra byte at the end, to prevent crashes
in case the string table is not terminated. */
if (shstrtabsize + 1 <= 1
+ || shstrtabsize > bfd_get_file_size (abfd)
|| bfd_seek (abfd, offset, SEEK_SET) != 0
|| (shstrtab = (bfd_byte *) bfd_alloc (abfd, shstrtabsize + 1)) == NULL)
shstrtab = NULL;