Parent: 0d989313b39e52eff0b4ad6d4adf0b3dfbaf1179
Author: Anderson Lizardo <anderson.lizardo@openbossa.org>
Committer: Johan Hedberg <johan.hedberg@intel.com>
Date: 2013-02-15 12:36:42
Tree: cebeca554650a14485332c9f650f1683ea4f7e1e
lib: Fix buffer overflow when processing SDP response rsp_count is either read or calculated from untrusted input, and therefore needs to be checked before being used as offset. The "plen" variable is appropriate because it is calculated as the sum of fixed and variable length fields, excluding the continuation state field, which has at least 1 byte for its own length field.
Diffstat
| M | lib/sdp.c | | | 11 | +++++++++++ |
1 files changed, 11 insertions(+), 0 deletions(-)