|
|
41da01 |
commit 05a9bd41a8ec0a9d580a8f420f41718bdd235446
|
|
|
41da01 |
Author: Nicolas Ruff <nruff@google.com>
|
|
|
41da01 |
Date: Mon Aug 18 15:22:48 2014 +0200
|
|
|
41da01 |
|
|
|
41da01 |
Do not accept a scaling factor of zero on PalmVNCSetScaleFactor and SetScale client->server messages. This would cause a division by zero and crash the server.
|
|
|
41da01 |
|
|
|
41da01 |
diff --git a/libvncserver/rfbserver.c b/libvncserver/rfbserver.c
|
|
|
41da01 |
index 7e43fe3..df7d74c 100644
|
|
|
41da01 |
--- a/libvncserver/rfbserver.c
|
|
|
41da01 |
+++ b/libvncserver/rfbserver.c
|
|
|
41da01 |
@@ -2491,6 +2491,13 @@ rfbProcessClientNormalMessage(rfbClientPtr cl)
|
|
|
41da01 |
rfbCloseClient(cl);
|
|
|
41da01 |
return;
|
|
|
41da01 |
}
|
|
|
41da01 |
+
|
|
|
41da01 |
+ if (msg.ssc.scale == 0) {
|
|
|
41da01 |
+ rfbLogPerror("rfbProcessClientNormalMessage: will not accept a scale factor of zero");
|
|
|
41da01 |
+ rfbCloseClient(cl);
|
|
|
41da01 |
+ return;
|
|
|
41da01 |
+ }
|
|
|
41da01 |
+
|
|
|
41da01 |
rfbStatRecordMessageRcvd(cl, msg.type, sz_rfbSetScaleMsg, sz_rfbSetScaleMsg);
|
|
|
41da01 |
rfbLog("rfbSetScale(%d)\n", msg.ssc.scale);
|
|
|
41da01 |
rfbScalingSetup(cl,cl->screen->width/msg.ssc.scale, cl->screen->height/msg.ssc.scale);
|
|
|
41da01 |
@@ -2507,6 +2514,13 @@ rfbProcessClientNormalMessage(rfbClientPtr cl)
|
|
|
41da01 |
rfbCloseClient(cl);
|
|
|
41da01 |
return;
|
|
|
41da01 |
}
|
|
|
41da01 |
+
|
|
|
41da01 |
+ if (msg.ssc.scale == 0) {
|
|
|
41da01 |
+ rfbLogPerror("rfbProcessClientNormalMessage: will not accept a scale factor of zero");
|
|
|
41da01 |
+ rfbCloseClient(cl);
|
|
|
41da01 |
+ return;
|
|
|
41da01 |
+ }
|
|
|
41da01 |
+
|
|
|
41da01 |
rfbStatRecordMessageRcvd(cl, msg.type, sz_rfbSetScaleMsg, sz_rfbSetScaleMsg);
|
|
|
41da01 |
rfbLog("rfbSetScale(%d)\n", msg.ssc.scale);
|
|
|
41da01 |
rfbScalingSetup(cl,cl->screen->width/msg.ssc.scale, cl->screen->height/msg.ssc.scale);
|