be8d9f3
From: David Bryant <david@wavpack.com>
be8d9f3
Date: Sun, 11 Feb 2018 16:37:47 -0800
be8d9f3
Subject: [PATCH] issue #28, fix buffer overflows and bad allocs on corrupt CAF
be8d9f3
 files
be8d9f3
be8d9f3
be8d9f3
diff --git a/cli/caff.c b/cli/caff.c
be8d9f3
index ae57c4b..6248a71 100644
be8d9f3
--- a/cli/caff.c
be8d9f3
+++ b/cli/caff.c
be8d9f3
@@ -89,8 +89,8 @@ typedef struct
be8d9f3
 
be8d9f3
 #define CAFChannelDescriptionFormat "LLLLL"
be8d9f3
 
be8d9f3
-static const char TMH_full [] = { 1,2,3,13,9,10,5,6,12,14,15,16,17,9,4,18,7,8,19,20,21 };
be8d9f3
-static const char TMH_std [] = { 1,2,3,11,8,9,5,6,10,12,13,14,15,7,4,16 };
be8d9f3
+static const char TMH_full [] = { 1,2,3,13,9,10,5,6,12,14,15,16,17,9,4,18,7,8,19,20,21,0 };
be8d9f3
+static const char TMH_std [] = { 1,2,3,11,8,9,5,6,10,12,13,14,15,7,4,16,0 };
be8d9f3
 
be8d9f3
 static struct {
be8d9f3
     uint32_t mChannelLayoutTag;     // Core Audio layout, 100 - 146 in high word, num channels in low word
be8d9f3
@@ -274,10 +274,19 @@ int ParseCaffHeaderConfig (FILE *infile, char *infilename, char *fourcc, Wavpack
be8d9f3
             }
be8d9f3
         }
be8d9f3
         else if (!strncmp (caf_chunk_header.mChunkType, "chan", 4)) {
be8d9f3
-            CAFChannelLayout *caf_channel_layout = malloc ((size_t) caf_chunk_header.mChunkSize);
be8d9f3
+            CAFChannelLayout *caf_channel_layout;
be8d9f3
 
be8d9f3
-            if (caf_chunk_header.mChunkSize < sizeof (CAFChannelLayout) ||
be8d9f3
-                !DoReadFile (infile, caf_channel_layout, (uint32_t) caf_chunk_header.mChunkSize, &bcount) ||
be8d9f3
+            if (caf_chunk_header.mChunkSize < sizeof (CAFChannelLayout) || caf_chunk_header.mChunkSize > 1024) {
be8d9f3
+                error_line ("this .CAF file has an invalid 'chan' chunk!");
be8d9f3
+                return WAVPACK_SOFT_ERROR;
be8d9f3
+            }
be8d9f3
+
be8d9f3
+            if (debug_logging_mode)
be8d9f3
+                error_line ("'chan' chunk is %d bytes", (int) caf_chunk_header.mChunkSize);
be8d9f3
+
be8d9f3
+            caf_channel_layout = malloc ((size_t) caf_chunk_header.mChunkSize);
be8d9f3
+
be8d9f3
+            if (!DoReadFile (infile, caf_channel_layout, (uint32_t) caf_chunk_header.mChunkSize, &bcount) ||
be8d9f3
                 bcount != caf_chunk_header.mChunkSize) {
be8d9f3
                     error_line ("%s is not a valid .CAF file!", infilename);
be8d9f3
                     free (caf_channel_layout);
be8d9f3
@@ -495,8 +504,15 @@ int ParseCaffHeaderConfig (FILE *infile, char *infilename, char *fourcc, Wavpack
be8d9f3
         }
be8d9f3
         else {          // just copy unknown chunks to output file
be8d9f3
 
be8d9f3
-            int bytes_to_copy = (uint32_t) caf_chunk_header.mChunkSize;
be8d9f3
-            char *buff = malloc (bytes_to_copy);
be8d9f3
+            uint32_t bytes_to_copy = (uint32_t) caf_chunk_header.mChunkSize;
be8d9f3
+            char *buff;
be8d9f3
+
be8d9f3
+            if (caf_chunk_header.mChunkSize < 0 || caf_chunk_header.mChunkSize > 1048576) {
be8d9f3
+                error_line ("%s is not a valid .CAF file!", infilename);
be8d9f3
+                return WAVPACK_SOFT_ERROR;
be8d9f3
+            }
be8d9f3
+
be8d9f3
+            buff = malloc (bytes_to_copy);
be8d9f3
 
be8d9f3
             if (debug_logging_mode)
be8d9f3
                 error_line ("extra unknown chunk \"%c%c%c%c\" of %d bytes",