mirror of
https://github.com/openwrt/openwrt.git
synced 2026-07-21 22:31:57 +04:00
7e7bd602ea
When growing the segment array in find_entry(), the memset() that zeroes the newly allocated slots computed the destination with redundant sizeof scaling: memset(segments + (num_segments * sizeof(struct tffs_entry_segment)), ...) segments is a typed pointer, so pointer arithmetic already scales by the element size. Multiplying the offset by sizeof again advances the destination by num_segments * sizeof^2 bytes, landing far outside the realloc()'d buffer and zeroing unrelated heap memory whenever a TFFS entry spans multiple segments that require array expansion. Drop the redundant multiplication so the memset targets segments[num_segments]. This is a robustness fix for malformed/corrupt TFFS content; the parser only reads the on-device nand-tffs MTD partition as root, so it is not considered security relevant. Reported-by: @Vasco0x4 Assisted-by: Claude:claude-opus-4-8 Link: https://github.com/openwrt/openwrt/pull/23763 Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
Userspace utilties for accessing TFFS (a name-value storage usually found in AVM Fritz!Box based devices)
Building
mkdir build
cd build
cmake /path/to/fritz_tffs_tools
make
Usage
All command line parameters are documented:
fritz_tffs_read -h
Show all entries from a TFFS partition dump (in the format: name=value):
fritz_tffs_read -i /path/to/tffs.dump -a
Read a TFFS partition and show all entries (in the format: name=value):
fritz_tffs_read -i /dev/mtdX -a
Output only the value of a specific key (this will only show the value):
fritz_tffs_read -i /dev/mtdX -n my_ipaddress
LICENSE
See LICENSE:
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 2 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License along
with this program; if not, write to the Free Software Foundation, Inc.,
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.