Hi,

my valgrind even says:

  valgrind: the 'impossible' happened:
     Killed by fatal signal

The trigger is an AAIP AL entry of length 4. The minimum size of an AL
entry is 6. This assumption made the code too optimistic about the
allocated length.

Fixed by:
  
https://dev.lovelyhq.com/libburnia/libisofs/commit/661b68ce8cfb77eabc2ce441fb306d7fb68e1bd0
  "Preventing buffer overflow with AAIP AL entry of insufficient size.
   Debian bug 872545. Thanks Jakub Wilk and American Fuzzy Lop."


Have a nice day :)

Thomas

Reply via email to