Commit: 7bf67b32709d828fafa26256b4c78331760c6e93
Parent: 2657fed2cec1551c6d5987aadf5586cb249e3ba5
Author: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Committer: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Date: 2018-11-02 13:09:28
Tree: 16c2efb162a1381c3f4668e1897926e5b3acde82

sdp: Fix not checking if cstate length cstate length should be smaller than cached length otherwise the request shall be considered invalid as the data is not within the cached buffer. An independent security researcher, Julian Rauchberger, has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program.

Diffstat

M src/sdpd-request.c | 74 +++++++++++++++++++++++++++++++++++++++- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

1 files changed, 39 insertions(+), 35 deletions(-)

View Full Diff | Patch