summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorRussell Bryant <russell@russellbryant.com>2007-07-17 20:58:40 +0000
committerRussell Bryant <russell@russellbryant.com>2007-07-17 20:58:40 +0000
commit91e2afe4e7c05a2adfe4d3e9b978d5b6ea119bdb (patch)
treed025d3e2d80410ad9fbca33a42cdcd6cf0f1a2f3
parent28ab081704340230c369a7d057be818c64f5b44b (diff)
Merged revisions 75450 via svnmerge from
https://origsvn.digium.com/svn/asterisk/branches/1.4 ................ r75450 | russell | 2007-07-17 15:57:56 -0500 (Tue, 17 Jul 2007) | 11 lines Merged revisions 75449 via svnmerge from https://origsvn.digium.com/svn/asterisk/branches/1.2 ........ r75449 | russell | 2007-07-17 15:57:09 -0500 (Tue, 17 Jul 2007) | 3 lines Properly check for the length in the skinny packet to prevent an invalid memcpy. (ASA-2007-016) ........ ................ git-svn-id: https://origsvn.digium.com/svn/asterisk/trunk@75451 65c4cc65-6c06-0410-ace0-fbb531ad65f3
-rw-r--r--channels/chan_skinny.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/channels/chan_skinny.c b/channels/chan_skinny.c
index 9a122cc6f..f55002d64 100644
--- a/channels/chan_skinny.c
+++ b/channels/chan_skinny.c
@@ -4587,7 +4587,7 @@ static int get_input(struct skinnysession *s)
}
dlen = letohl(*(int *)s->inbuf);
- if (dlen < 0) {
+ if (dlen < 4) {
ast_log(LOG_WARNING, "Skinny Client sent invalid data.\n");
ast_mutex_unlock(&s->lock);
return -1;