diff options
author | russell <russell@f38db490-d61c-443f-a65b-d21fe96a405b> | 2007-07-17 20:57:09 +0000 |
---|---|---|
committer | russell <russell@f38db490-d61c-443f-a65b-d21fe96a405b> | 2007-07-17 20:57:09 +0000 |
commit | d3ac3d7e46acf8dc3e0926a1b7a36d20f5807d2d (patch) | |
tree | c24f24ebe3a6c2bd90ccb026facbf03e6720c37d /channels | |
parent | 4c9df6e31f645075f68f03772cd2349fd5f4de37 (diff) |
Properly check for the length in the skinny packet to prevent an invalid memcpy.
(ASA-2007-016)
git-svn-id: http://svn.digium.com/svn/asterisk/branches/1.2@75449 f38db490-d61c-443f-a65b-d21fe96a405b
Diffstat (limited to 'channels')
-rw-r--r-- | channels/chan_skinny.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/channels/chan_skinny.c b/channels/chan_skinny.c index 3cfd9d646..c9d3f8854 100644 --- a/channels/chan_skinny.c +++ b/channels/chan_skinny.c @@ -2862,7 +2862,7 @@ static int get_input(struct skinnysession *s) return -1; } dlen = letohl(*(int *)s->inbuf); - if (dlen < 0) { + if (dlen < 4) { ast_log(LOG_WARNING, "Skinny Client sent invalid data.\n"); return -1; } |