提交 c5df5913 编写于 作者: R Roel Kluin 提交者: Linus Torvalds

ncpfs: read buffer overflow

This function uses signed integers for the unix_date and local variables -
if a negative number is supplied and the leap-year condition is not met,
month will be 0, leading to a later read of day_n[-1]
Signed-off-by: NRoel Kluin <roel.kluin@gmail.com>
Cc: Petr Vandrovec <VANDROVE@vc.cvut.cz>
Signed-off-by: NAndrew Morton <akpm@linux-foundation.org>
Signed-off-by: NLinus Torvalds <torvalds@linux-foundation.org>
上级 a7e3108c
...@@ -1241,7 +1241,7 @@ ncp_date_unix2dos(int unix_date, __le16 *time, __le16 *date) ...@@ -1241,7 +1241,7 @@ ncp_date_unix2dos(int unix_date, __le16 *time, __le16 *date)
month = 2; month = 2;
} else { } else {
nl_day = (year & 3) || day <= 59 ? day : day - 1; nl_day = (year & 3) || day <= 59 ? day : day - 1;
for (month = 0; month < 12; month++) for (month = 1; month < 12; month++)
if (day_n[month] > nl_day) if (day_n[month] > nl_day)
break; break;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册