Merge pull request #620 from bootc/cve-2017-12087

Fix CVE-2017-12087 in bundled tinysvcmdns (development branch)
This commit is contained in:
Mike Brady
2017-11-23 15:20:36 +00:00
committed by GitHub
+16 -4
View File
@@ -123,21 +123,33 @@ uint8_t *join_nlabel(const uint8_t *n1, const uint8_t *n2) {
char *nlabel_to_str(const uint8_t *name) {
char *label, *labelp;
const uint8_t *p;
size_t buf_len = 256;
assert(name != NULL);
label = labelp = malloc(256);
label = labelp = malloc(buf_len);
if (label) {
for (p = name; *p; p++) {
strncpy(labelp, (char *)p + 1, *p);
labelp += *p;
uint8_t label_len = *p;
if (buf_len <= label_len)
break;
strncpy(labelp, (char *)p + 1, label_len);
labelp += label_len;
*labelp = '.';
labelp++;
p += *p;
buf_len -= label_len + 1;
p += label_len;
}
// avoid writing NULL past end of buffer
if (buf_len == 0)
labelp--;
*labelp = '\0';
} else {
die("could not allocate memory for \"label\" in tinysvcmdns.c.");