aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorrussell <russell@f38db490-d61c-443f-a65b-d21fe96a405b>2007-07-17 20:57:09 +0000
committerrussell <russell@f38db490-d61c-443f-a65b-d21fe96a405b>2007-07-17 20:57:09 +0000
commitd3ac3d7e46acf8dc3e0926a1b7a36d20f5807d2d (patch)
treec24f24ebe3a6c2bd90ccb026facbf03e6720c37d
parent4c9df6e31f645075f68f03772cd2349fd5f4de37 (diff)
Properly check for the length in the skinny packet to prevent an invalid memcpy.
(ASA-2007-016) git-svn-id: http://svn.digium.com/svn/asterisk/branches/1.2@75449 f38db490-d61c-443f-a65b-d21fe96a405b
-rw-r--r--channels/chan_skinny.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/channels/chan_skinny.c b/channels/chan_skinny.c
index 3cfd9d646..c9d3f8854 100644
--- a/channels/chan_skinny.c
+++ b/channels/chan_skinny.c
@@ -2862,7 +2862,7 @@ static int get_input(struct skinnysession *s)
return -1;
}
dlen = letohl(*(int *)s->inbuf);
- if (dlen < 0) {
+ if (dlen < 4) {
ast_log(LOG_WARNING, "Skinny Client sent invalid data.\n");
return -1;
}