Add a bound check for sas7bcat_parse_value_labels when finding the offset of labels.#303
Closed
kiwiwarmnfuzzy wants to merge 1 commit intoWizardMac:devfrom
Closed
Conversation
`lbp1` will try to chase and read as many value labels as `label_count_capacity`, which may result in accessing memory locations pass the allocated region, especially for malformed data. This also results in Address sanitizer error on some inputs. Add a bounds check to avoid it.
Author
|
@evanmiller Hi there! Please take a look when you have time - this addresses one of the vulnerabilities identified by our fuzzing tool; realistically, this can happen with incorrect or malformed data. |
Contributor
|
Hi, I'm just confused because I thought line 63 was performing this check But maybe I'm missing something? |
Contributor
|
Ah, looks like a regression introduced in #293. I will prepare a fix. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
lbp1will try to chase and read as many value labels aslabel_count_capacity, which may result in accessing memory locations past the allocated region, especially for malformed data. This also results in Address sanitizer error on some inputs. Add a bounds check to avoid it.Closes #299
Maybe related to #285