diff options
| author | JosJuice <josjuice@gmail.com> | 2017-05-26 23:10:31 +0200 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2017-05-26 23:10:31 +0200 |
| commit | aa33fabded3ad9300fed0e68c2596decefcd65e5 (patch) | |
| tree | 57fca34d238538551fa8f67f22c3531d404a9890 /Source/Core/DiscIO/VolumeWiiCrypted.cpp | |
| parent | 700a443c2a89caacbbd6a23f2c2c5991745f1515 (diff) | |
| parent | b5a2f34a3778a1921e2d448557d4557807364f6f (diff) | |
Merge pull request #5483 from leoetlino/max-tmd-size
Check TMD sizes using the actual constant
Diffstat (limited to 'Source/Core/DiscIO/VolumeWiiCrypted.cpp')
| -rw-r--r-- | Source/Core/DiscIO/VolumeWiiCrypted.cpp | 10 |
1 files changed, 4 insertions, 6 deletions
diff --git a/Source/Core/DiscIO/VolumeWiiCrypted.cpp b/Source/Core/DiscIO/VolumeWiiCrypted.cpp index c2826c6515..5e088a9422 100644 --- a/Source/Core/DiscIO/VolumeWiiCrypted.cpp +++ b/Source/Core/DiscIO/VolumeWiiCrypted.cpp @@ -81,13 +81,11 @@ CVolumeWiiCrypted::CVolumeWiiCrypted(std::unique_ptr<IBlobReader> reader) if (!m_pReader->ReadSwapped(partition_offset + 0x2a8, &tmd_address)) continue; tmd_address <<= 2; - if (tmd_size > 1024 * 1024 * 4) + if (!IOS::ES::IsValidTMDSize(tmd_size)) { - // The size is checked so that a malicious or corrupt ISO - // can't force Dolphin to allocate up to 4 GiB of memory. - // 4 MiB should be much bigger than the size of TMDs and much smaller - // than the amount of RAM in a computer that can run Dolphin. - PanicAlert("TMD > 4 MiB"); + // This check is normally done by ES in ES_DiVerify, but that would happen too late + // (after allocating the buffer), so we do the check here. + PanicAlert("Invalid TMD size"); continue; } std::vector<u8> tmd_buffer(tmd_size); |
