From c6e2a119b75becab7a811f32cbbe38a6a0dc3776 Mon Sep 17 00:00:00 2001 From: Russell Bryant Date: Tue, 17 Jul 2007 20:57:56 +0000 Subject: [PATCH] Merged revisions 75449 via svnmerge from https://origsvn.digium.com/svn/asterisk/branches/1.2 ........ r75449 | russell | 2007-07-17 15:57:09 -0500 (Tue, 17 Jul 2007) | 3 lines Properly check for the length in the skinny packet to prevent an invalid memcpy. (ASA-2007-016) ........ git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/1.4@75450 65c4cc65-6c06-0410-ace0-fbb531ad65f3 --- channels/chan_skinny.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/channels/chan_skinny.c b/channels/chan_skinny.c index 64b22080e1..841778c6eb 100644 --- a/channels/chan_skinny.c +++ b/channels/chan_skinny.c @@ -4286,7 +4286,7 @@ static int get_input(struct skinnysession *s) } dlen = letohl(*(int *)s->inbuf); - if (dlen < 0) { + if (dlen < 4) { ast_log(LOG_WARNING, "Skinny Client sent invalid data.\n"); ast_mutex_unlock(&s->lock); return -1;