Blame SOURCES/wireshark-1.10.14-CVE-2015-6245.patch

affdba
diff --git a/epan/dissectors/packet-gsm_rlcmac.c b/epan/dissectors/packet-gsm_rlcmac.c
affdba
index e4eac08..7a783ef 100644
affdba
--- a/epan/dissectors/packet-gsm_rlcmac.c
affdba
+++ b/epan/dissectors/packet-gsm_rlcmac.c
affdba
@@ -60,7 +60,7 @@
affdba
 /* private typedefs */
affdba
 typedef struct
affdba
 {
affdba
-   guint8 offset;
affdba
+   gint   offset;
affdba
    guint8 li;
affdba
 }length_indicator_t;
affdba
 
affdba
@@ -6737,10 +6737,11 @@ static const value_string gsm_rlcmac_t3192_vals[] = {
affdba
   { 0, NULL}
affdba
 };
affdba
 
affdba
-static guint8 construct_gprs_data_segment_li_array(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, guint8 initial_offset, guint8 *li_count, length_indicator_t *li_array, guint64 *e)
affdba
+static gint construct_gprs_data_segment_li_array(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, guint8 initial_offset, guint8 *li_count, length_indicator_t *li_array, guint64 *e)
affdba
 {
affdba
-    guint8 offset = initial_offset, li_array_size = *li_count;
affdba
-	proto_item 	*item;
affdba
+    gint        offset = initial_offset;
affdba
+    guint8      li_array_size = *li_count;
affdba
+    proto_item  *item;
affdba
 
affdba
     *li_count = 0;
affdba
     while(*e == 0)
affdba
@@ -6763,15 +6764,15 @@ static guint8 construct_gprs_data_segment_li_array(tvbuff_t *tvb, proto_tree *tr
affdba
     return (offset - initial_offset);
affdba
 }
affdba
 
affdba
-static guint8 construct_egprs_data_segment_li_array(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, guint8 initial_offset, guint8 *li_count, length_indicator_t *li_array, guint64 *e)
affdba
+static gint construct_egprs_data_segment_li_array(tvbuff_t *tvb, proto_tree *tree, packet_info *pinfo, guint8 initial_offset, guint8 *li_count, length_indicator_t *li_array, guint64 *e)
affdba
 {
affdba
-    guint8 offset = initial_offset, li_array_size = *li_count;
affdba
-	proto_item 	*item;
affdba
+    gint        offset = initial_offset;
affdba
+    guint8      li_array_size = *li_count;
affdba
+    proto_item  *item;
affdba
 
affdba
     *li_count = 0;
affdba
     while(*e == 0)
affdba
     {
affdba
-        DISSECTOR_ASSERT(*li_count < li_array_size);
affdba
         item = proto_tree_add_bits_item(tree, hf_li, tvb, offset * 8, 7, ENC_BIG_ENDIAN);
affdba
         proto_tree_add_bits_ret_val(tree, hf_e, tvb, (offset * 8) + 7, 1, e, ENC_BIG_ENDIAN);
affdba
         if(*li_count < li_array_size)
affdba
@@ -7466,7 +7467,7 @@ dissect_ul_gprs_block(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, RlcMa
affdba
    csnStream_t      ar;
affdba
    guint8 payload_type = tvb_get_bits8(tvb, 0, 2);
affdba
    guint16 bit_length = tvb_length(tvb) * 8;
affdba
-   guint16 bit_offset = 0;
affdba
+   gint bit_offset = 0;
affdba
    length_indicator_t li_array[10];
affdba
    guint8 li_count = array_length(li_array);
affdba
 
affdba
@@ -7595,7 +7596,7 @@ dissect_egprs_ul_data_block(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree,
affdba
 {
affdba
    proto_item   *ti = NULL;
affdba
    proto_tree *data_tree = NULL;
affdba
-   guint8 offset = 0;
affdba
+   gint offset = 0;
affdba
    length_indicator_t li_array[20];
affdba
    guint8 li_count = array_length(li_array);
affdba
    guint64 e, tlli_i;
affdba
@@ -7655,7 +7656,8 @@ dissect_egprs_dl_data_block(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree,
affdba
 {
affdba
     proto_item      *ti = NULL;
affdba
     proto_tree      *data_tree = NULL;
affdba
-    guint16 offset = 0, block_number;
affdba
+    gint offset = 0;
affdba
+    guint16 block_number;
affdba
     length_indicator_t li_array[20];
affdba
     guint8 li_count = array_length(li_array);
affdba
     guint64 fbi, e;