From c4e3113a8df53ba60c36829c8b2d583c2d5e529d Mon Sep 17 00:00:00 2001 From: Frediano Ziglio Date: Tue, 29 Nov 2016 16:46:56 +0000 Subject: [PATCH] main-channel: Prevent overflow reading messages from client Caller is supposed the function return a buffer able to store size bytes. Signed-off-by: Frediano Ziglio --- server/main_channel.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/server/main_channel.c b/server/main_channel.c index 54718ba..bedff46 100644 --- a/server/main_channel.c +++ b/server/main_channel.c @@ -1030,6 +1030,9 @@ static uint8_t *main_channel_alloc_msg_rcv_buf(RedChannelClient *rcc, if (type == SPICE_MSGC_MAIN_AGENT_DATA) { return reds_get_agent_data_buffer(mcc, size); + } else if (size > sizeof(main_chan->recv_buf)) { + /* message too large, caller will log a message and close the connection */ + return NULL; } else { return main_chan->recv_buf; } -- 2.9.3