From: Nick Clifton Date: Fri, 31 Oct 2014 18:00:55 +0000 (+0000) Subject: Fix an (almost) infinite loop in the tekhex parser. X-Git-Tag: gdb-7.9.0-release~781 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=690725fa0d98ae52c991f4b3ea58b6b47b4fbc80;p=external%2Fbinutils.git Fix an (almost) infinite loop in the tekhex parser. PR binutils/17512 * tekhex.c (first_phase): Check that the section range is sane. --- diff --git a/bfd/ChangeLog b/bfd/ChangeLog index accbcc9..d861257 100644 --- a/bfd/ChangeLog +++ b/bfd/ChangeLog @@ -5,6 +5,7 @@ symbol table bigger than the file. * elf.c (bfd_elf_get_str_section): Do not try to load a string table bigger than the file. + * tekhex.c (first_phase): Check that the section range is sane. 2014-10-30 Nick Clifton diff --git a/bfd/tekhex.c b/bfd/tekhex.c index 2220d50..85f5593 100644 --- a/bfd/tekhex.c +++ b/bfd/tekhex.c @@ -403,6 +403,9 @@ first_phase (bfd *abfd, int type, char *src) if (!getvalue (&src, &val)) return FALSE; section->size = val - section->vma; + /* PR binutils/17512: Make sure that the size is sane. */ + if (section->size > (bfd_size_type) bfd_get_size (abfd)) + return FALSE; section->flags = SEC_HAS_CONTENTS | SEC_LOAD | SEC_ALLOC; break; case '0':