From b5a2f34a3778a1921e2d448557d4557807364f6f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?L=C3=A9o=20Lam?= Date: Fri, 26 May 2017 11:23:11 +0200 Subject: Check TMD sizes using the actual constant 0x49e4 is the actual maximum TMD size (which is checked against in ES). IsValidTMDSize is added to ESFormats to avoid duplicating the constant. --- Source/Core/DiscIO/VolumeWiiCrypted.cpp | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) (limited to 'Source/Core/DiscIO/VolumeWiiCrypted.cpp') diff --git a/Source/Core/DiscIO/VolumeWiiCrypted.cpp b/Source/Core/DiscIO/VolumeWiiCrypted.cpp index c2826c6515..5e088a9422 100644 --- a/Source/Core/DiscIO/VolumeWiiCrypted.cpp +++ b/Source/Core/DiscIO/VolumeWiiCrypted.cpp @@ -81,13 +81,11 @@ CVolumeWiiCrypted::CVolumeWiiCrypted(std::unique_ptr reader) if (!m_pReader->ReadSwapped(partition_offset + 0x2a8, &tmd_address)) continue; tmd_address <<= 2; - if (tmd_size > 1024 * 1024 * 4) + if (!IOS::ES::IsValidTMDSize(tmd_size)) { - // The size is checked so that a malicious or corrupt ISO - // can't force Dolphin to allocate up to 4 GiB of memory. - // 4 MiB should be much bigger than the size of TMDs and much smaller - // than the amount of RAM in a computer that can run Dolphin. - PanicAlert("TMD > 4 MiB"); + // This check is normally done by ES in ES_DiVerify, but that would happen too late + // (after allocating the buffer), so we do the check here. + PanicAlert("Invalid TMD size"); continue; } std::vector tmd_buffer(tmd_size); -- cgit v1.2.3