c4e8dc8
Fix for CVE-2008-1389, applied upstream in 0.94
c4e8dc8
svn diff -c 4157 http://svn.clamav.net/svn/clamav-devel/trunk/
c4e8dc8
c4e8dc8
diff -pruN clamav-0.93.3.orig/libclamav/chmunpack.c clamav-0.93.3/libclamav/chmunpack.c
c4e8dc8
--- clamav-0.93.3.orig/libclamav/chmunpack.c	2008-04-07 11:18:42.000000000 +0200
c4e8dc8
+++ clamav-0.93.3/libclamav/chmunpack.c	2008-11-13 17:50:49.000000000 +0100
c4e8dc8
@@ -449,7 +449,7 @@ static int read_chunk(chm_metadata_t *me
c4e8dc8
 	cli_dbgmsg("in read_chunk\n");
c4e8dc8
 
c4e8dc8
 	if (metadata->itsp_hdr.block_len < 8 || metadata->itsp_hdr.block_len > 33554432) {
c4e8dc8
-		return FALSE;
c4e8dc8
+		return CL_EFORMAT;
c4e8dc8
 	}
c4e8dc8
 
c4e8dc8
 	if (metadata->m_area != NULL) {
c4e8dc8
@@ -911,7 +911,9 @@ int cli_chm_open(int fd, const char *dir
c4e8dc8
 			cli_dbgmsg("read_chunk failed");
c4e8dc8
 			goto abort;
c4e8dc8
 		}
c4e8dc8
-		read_control_entries(metadata);
c4e8dc8
+		if (read_control_entries(metadata) == FALSE) {
c4e8dc8
+			goto abort;
c4e8dc8
+		}
c4e8dc8
 		metadata->num_chunks--;
c4e8dc8
 		metadata->chunk_offset += metadata->itsp_hdr.block_len;
c4e8dc8
 	}