lzop: add overflow check
authorDenys Vlasenko <vda.linux@googlemail.com>
Mon, 30 Jun 2014 08:14:34 +0000 (10:14 +0200)
committerMike Frysinger <vapier@gentoo.org>
Tue, 21 Oct 2014 12:41:37 +0000 (08:41 -0400)
commit5698ff93233b47218a677fd7facd8cc90211d1a4
treec5ebb982e16af7ea542cf1999349df54aed87175
parentd9e0c438e10e2155513e5d26498af472c5137d65
lzop: add overflow check

See CVE-2014-4607
http://www.openwall.com/lists/oss-security/2014/06/26/20

function                                             old     new   delta
lzo1x_decompress_safe                               1010    1031     +21

Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
Signed-off-by: Mike Frysinger <vapier@gentoo.org>
(cherry picked from commit a9dc7c2f59dc5e92870d2d46316ea5c1f14740e3)
archival/libarchive/liblzo.h
archival/libarchive/lzo1x_d.c