Fix heap-buffer-overflow in safe_browsing::dmg::HFSBTreeIterator::Next.
The BTree leaf structure contains a length and embedded string. Check that the length of the embedded string is not larger than node containing the leaf. Bug: 776307 Test: Covered by fuzzer. Change-Id: I2c39c55b42da34bcc8cb26c481e269b66b19811d Reviewed-on: https://chromium-review.googlesource.com/728084Reviewed-by:Varun Khaneja <vakh@chromium.org> Commit-Queue: Robert Sesek <rsesek@chromium.org> Cr-Commit-Position: refs/heads/master@{#510119}
Showing
Please register or sign in to comment