This is an automated email from the git hooks/post-receive script. guillem pushed a commit to branch master in repository dpkg.
View the commit online: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=a1f9ccf08ddc99e4e3f1ead01abb6a8d8d506b3a commit a1f9ccf08ddc99e4e3f1ead01abb6a8d8d506b3a Author: Guillem Jover <[email protected]> AuthorDate: Wed Mar 6 03:52:10 2019 +0100 libdpkg: Handle non end-of-tape errors from tar_header_decode() We need to assign a status value in the non end-of-tape branch, otherwise we are using an uninitialized value, which might be anything, and could end up making the code proceed even if the archive is damaged/broken, etc. --- debian/changelog | 1 + lib/dpkg/tarfn.c | 2 ++ 2 files changed, 3 insertions(+) diff --git a/debian/changelog b/debian/changelog index e600badcd..43153c343 100644 --- a/debian/changelog +++ b/debian/changelog @@ -4,6 +4,7 @@ dpkg (1.19.6) UNRELEASED; urgency=medium * libdpkg: Add a new TAR_FORMAT_UNKNOWN enum value. * libdpkg: Set tar_entry to zero on tar_entry_destroy(), to avoid double free()s and the subsequent crashes. + * libdpkg: Handle non end-of-tape errors from tar_header_decode(). * Packaging: - Update usertags. - Install a lintian profile for dpkg based on the debian profile, so that diff --git a/lib/dpkg/tarfn.c b/lib/dpkg/tarfn.c index 757e0e323..7ccdae389 100644 --- a/lib/dpkg/tarfn.c +++ b/lib/dpkg/tarfn.c @@ -466,6 +466,8 @@ tar_extractor(struct tar_archive *tar) if (h.name[0] == '\0') { /* End Of Tape. */ status = 0; + } else { + status = -1; } tar_entry_destroy(&h); break; -- Dpkg.Org's dpkg

