This is an automated email from the git hooks/post-receive script.

guillem pushed a commit to branch master
in repository dpkg.

View the commit online:
https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=a1f9ccf08ddc99e4e3f1ead01abb6a8d8d506b3a

commit a1f9ccf08ddc99e4e3f1ead01abb6a8d8d506b3a
Author: Guillem Jover <[email protected]>
AuthorDate: Wed Mar 6 03:52:10 2019 +0100

    libdpkg: Handle non end-of-tape errors from tar_header_decode()
    
    We need to assign a status value in the non end-of-tape branch,
    otherwise we are using an uninitialized value, which might be anything,
    and could end up making the code proceed even if the archive is
    damaged/broken, etc.
---
 debian/changelog | 1 +
 lib/dpkg/tarfn.c | 2 ++
 2 files changed, 3 insertions(+)

diff --git a/debian/changelog b/debian/changelog
index e600badcd..43153c343 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -4,6 +4,7 @@ dpkg (1.19.6) UNRELEASED; urgency=medium
   * libdpkg: Add a new TAR_FORMAT_UNKNOWN enum value.
   * libdpkg: Set tar_entry to zero on tar_entry_destroy(), to avoid double
     free()s and the subsequent crashes.
+  * libdpkg: Handle non end-of-tape errors from tar_header_decode().
   * Packaging:
     - Update usertags.
     - Install a lintian profile for dpkg based on the debian profile, so that
diff --git a/lib/dpkg/tarfn.c b/lib/dpkg/tarfn.c
index 757e0e323..7ccdae389 100644
--- a/lib/dpkg/tarfn.c
+++ b/lib/dpkg/tarfn.c
@@ -466,6 +466,8 @@ tar_extractor(struct tar_archive *tar)
                        if (h.name[0] == '\0') {
                                /* End Of Tape. */
                                status = 0;
+                       } else {
+                               status = -1;
                        }
                        tar_entry_destroy(&h);
                        break;

-- 
Dpkg.Org's dpkg

Reply via email to