# --- SDE-COPYRIGHT-NOTE-BEGIN --- # This copyright note is auto-generated by ./scripts/Create-CopyPatch. # # Filename: package/.../ncompress/CVE-2006-1168.patch # Copyright (C) 2006 The OpenSDE Project # Copyright (C) 2006 The T2 SDE Project # # More information can be found in the files COPYING and README. # # This patch file is dual-licensed. It is available under the license the # patched project is licensed under, as long as it is an OpenSource license # as defined at http://www.opensource.org/ (e.g. BSD, X11) or under the terms # of the GNU General Public License as published by the Free Software # Foundation; either version 2 of the License, or (at your option) any later # version. # --- SDE-COPYRIGHT-NOTE-END --- diff -Nur ncompress-4.2.4-orig/compress42.c ncompress-4.2.4/compress42.c --- ncompress-4.2.4-orig/compress42.c 1992-10-28 13:10:53.000000000 +0200 +++ ncompress-4.2.4/compress42.c 2006-08-16 11:02:28.000000000 +0300 @@ -1737,7 +1737,7 @@ code = oldcode; } - while ((cmp_code_int)code >= (cmp_code_int)256) + while ((cmp_code_int)code >= (cmp_code_int)256 && stackp >= &htabof(0)) { /* Generate output characters in reverse order */ *--stackp = tab_suffixof(code); code = tab_prefixof(code);