]> git.ipfire.org Git - thirdparty/asterisk.git/commitdiff
Properly check for the length in the skinny packet to prevent an invalid memcpy.
authorRussell Bryant <russell@russellbryant.com>
Tue, 17 Jul 2007 20:57:09 +0000 (20:57 +0000)
committerRussell Bryant <russell@russellbryant.com>
Tue, 17 Jul 2007 20:57:09 +0000 (20:57 +0000)
(ASA-2007-016)

git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/1.2@75449 65c4cc65-6c06-0410-ace0-fbb531ad65f3

channels/chan_skinny.c

index 3cfd9d64687daf56d4ae74c882653327325a1a97..c9d3f885487781d60a3e6d81ec2e9d71e3f4c29b 100644 (file)
@@ -2862,7 +2862,7 @@ static int get_input(struct skinnysession *s)
                        return -1;
                }
                dlen = letohl(*(int *)s->inbuf);
-               if (dlen < 0) {
+               if (dlen < 4) {
                        ast_log(LOG_WARNING, "Skinny Client sent invalid data.\n");
                        return -1;
                }