[asterisk-commits] russell: branch 1.4 r75450 - in /branches/1.4: ./ channels/chan_skinny.c

SVN commits to the Asterisk project asterisk-commits at lists.digium.com
Tue Jul 17 15:57:57 CDT 2007


Author: russell
Date: Tue Jul 17 15:57:56 2007
New Revision: 75450

URL: http://svn.digium.com/view/asterisk?view=rev&rev=75450
Log:
Merged revisions 75449 via svnmerge from 
https://origsvn.digium.com/svn/asterisk/branches/1.2

........
r75449 | russell | 2007-07-17 15:57:09 -0500 (Tue, 17 Jul 2007) | 3 lines

Properly check for the length in the skinny packet to prevent an invalid memcpy.
(ASA-2007-016)

........

Modified:
    branches/1.4/   (props changed)
    branches/1.4/channels/chan_skinny.c

Propchange: branches/1.4/
------------------------------------------------------------------------------
Binary property 'branch-1.2-merged' - no diff available.

Modified: branches/1.4/channels/chan_skinny.c
URL: http://svn.digium.com/view/asterisk/branches/1.4/channels/chan_skinny.c?view=diff&rev=75450&r1=75449&r2=75450
==============================================================================
--- branches/1.4/channels/chan_skinny.c (original)
+++ branches/1.4/channels/chan_skinny.c Tue Jul 17 15:57:56 2007
@@ -4286,7 +4286,7 @@
 		}
 		
 		dlen = letohl(*(int *)s->inbuf);
-		if (dlen < 0) {
+		if (dlen < 4) {
 			ast_log(LOG_WARNING, "Skinny Client sent invalid data.\n");
 			ast_mutex_unlock(&s->lock);
 			return -1;




More information about the asterisk-commits mailing list