aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authormnicholson <mnicholson@f38db490-d61c-443f-a65b-d21fe96a405b>2011-01-11 18:34:40 +0000
committermnicholson <mnicholson@f38db490-d61c-443f-a65b-d21fe96a405b>2011-01-11 18:34:40 +0000
commit161a4a9df35f9406a2423518ea444a708c2e7261 (patch)
tree1eb838b38caeb014531ea0a73f7710c9586730c9
parent18c1e89dad819a5e486984a4ac749f7163b535f1 (diff)
Prevent buffer overflows in ast_uri_encode()
ABE-2705 git-svn-id: http://svn.digium.com/svn/asterisk/branches/1.4@301305 f38db490-d61c-443f-a65b-d21fe96a405b
-rw-r--r--main/utils.c27
1 files changed, 13 insertions, 14 deletions
diff --git a/main/utils.c b/main/utils.c
index 17e21390e..70c66547e 100644
--- a/main/utils.c
+++ b/main/utils.c
@@ -388,28 +388,27 @@ char *ast_uri_encode(const char *string, char *outbuf, int buflen, int doreserve
char *reserved = ";/?:@&=+$,# "; /* Reserved chars */
const char *ptr = string; /* Start with the string */
- char *out = NULL;
- char *buf = NULL;
+ char *out = outbuf;
- ast_copy_string(outbuf, string, buflen);
-
- /* If there's no characters to convert, just go through and don't do anything */
- while (*ptr) {
+ /* If there's no characters to convert, just go through and copy the string */
+ while (*ptr && out - outbuf < buflen - 1) {
if ((*ptr < 32) || (doreserved && strchr(reserved, *ptr))) {
- /* Oops, we need to start working here */
- if (!buf) {
- buf = outbuf;
- out = buf + (ptr - string) ; /* Set output ptr */
+ if (out - outbuf >= buflen - 3) {
+ break;
}
+
out += sprintf(out, "%%%02x", (unsigned char) *ptr);
- } else if (buf) {
- *out = *ptr; /* Continue copying the string */
+ } else {
+ *out = *ptr; /* copy the character */
out++;
- }
+ }
ptr++;
}
- if (buf)
+
+ if (buflen) {
*out = '\0';
+ }
+
return outbuf;
}