Parcourir la source

Add sanity checks for fseek and ftell return values

In theory, these calls could fail, but it is not really likely to
happen in practice in the use case here. Anyway, check that they do
not return an error before accepting the length of the file.
Jouni Malinen il y a 14 ans
Parent
commit
fe655a8402
1 fichiers modifiés avec 10 ajouts et 3 suppressions
  1. 10 3
      src/utils/os_unix.c

+ 10 - 3
src/utils/os_unix.c

@@ -315,14 +315,21 @@ char * os_readfile(const char *name, size_t *len)
 {
 {
 	FILE *f;
 	FILE *f;
 	char *buf;
 	char *buf;
+	long pos;
 
 
 	f = fopen(name, "rb");
 	f = fopen(name, "rb");
 	if (f == NULL)
 	if (f == NULL)
 		return NULL;
 		return NULL;
 
 
-	fseek(f, 0, SEEK_END);
-	*len = ftell(f);
-	fseek(f, 0, SEEK_SET);
+	if (fseek(f, 0, SEEK_END) < 0 || (pos = ftell(f)) < 0) {
+		fclose(f);
+		return NULL;
+	}
+	*len = pos;
+	if (fseek(f, 0, SEEK_SET) < 0) {
+		fclose(f);
+		return NULL;
+	}
 
 
 	buf = os_malloc(*len);
 	buf = os_malloc(*len);
 	if (buf == NULL) {
 	if (buf == NULL) {