aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorTatsuya Kinoshita <tats@debian.org>2016-11-21 14:35:54 +0000
committerTatsuya Kinoshita <tats@debian.org>2016-11-21 14:35:54 +0000
commit2a470ab78ab859e934b577dd80bf0079314ffaef (patch)
tree2e5d9972255542a353e9751a9d35dd86cd4cd08c
parentNew patch 914_curline.patch to fix near-null deref [CVE-2016-9440] (diff)
downloadw3m-2a470ab78ab859e934b577dd80bf0079314ffaef.tar.gz
w3m-2a470ab78ab859e934b577dd80bf0079314ffaef.zip
New patch 915_table-alt.patch to fix near-null deref [CVE-2016-9441]
-rw-r--r--debian/patches/915_table-alt.patch18
-rw-r--r--debian/patches/series1
2 files changed, 19 insertions, 0 deletions
diff --git a/debian/patches/915_table-alt.patch b/debian/patches/915_table-alt.patch
new file mode 100644
index 0000000..3d1eee2
--- /dev/null
+++ b/debian/patches/915_table-alt.patch
@@ -0,0 +1,18 @@
+Subject: Prevent segfault with malformed table_alt
+Author: Tatsuya Kinoshita <tats@debian.org>
+Bug-Debian: https://github.com/tats/w3m/issues/24 [CVE-2016-9441]
+Origin: https://anonscm.debian.org/cgit/collab-maint/w3m.git/commit/?id=a6257663824c63abb3c62c4dd62455fe6f63d958
+
+diff --git a/table.c b/table.c
+index a54ea01..022effe 100644
+--- a/table.c
++++ b/table.c
+@@ -761,7 +761,7 @@ do_refill(struct table *tbl, int row, int col, int maxlimit)
+ struct parsed_tag *tag;
+ if ((tag = parse_tag(&p, TRUE)) != NULL)
+ parsedtag_get_value(tag, ATTR_TID, &id);
+- if (id >= 0 && id < tbl->ntable) {
++ if (id >= 0 && id < tbl->ntable && tbl->tables[id].ptr) {
+ int alignment;
+ TextLineListItem *ti;
+ struct table *t = tbl->tables[id].ptr;
diff --git a/debian/patches/series b/debian/patches/series
index 8e9b809..fb9b5b7 100644
--- a/debian/patches/series
+++ b/debian/patches/series
@@ -50,3 +50,4 @@
912_i-dd.patch
913_tabwidth.patch
914_curline.patch
+915_table-alt.patch