Fix OOB reads and infinite loop in TLV and DMAP parsers
pair_ap/pair-tlv.c (pair_tlv_parse): - Add bounds check before reading type and length bytes (i + 2 > length) - Fix off-by-one in chunked TLV scan loop (j + 1 < length) - Add bounds checks inside data copy loop to prevent OOB memcpy - Add else branch to advance index when size == 0 (prevents infinite loop) rtsp.c (handle_set_parameter_metadata): - Require 8 bytes remaining for tag + length fields (off + 8 <= cl) - Validate value length against remaining buffer before read Reported-by: Tristan Madani <tristan@talencesecurity.com> Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
This commit is contained in:
@@ -3275,7 +3275,7 @@ static void handle_set_parameter_metadata(__attribute__((unused)) rtsp_conn_info
|
||||
unsigned int off = 8;
|
||||
|
||||
uint32_t itag, vl;
|
||||
while (off < cl) {
|
||||
while (off + 8 <= cl) {
|
||||
// pick up the metadata tag as an unsigned longint
|
||||
memcpy(&itag, (uint32_t *)(cp + off), sizeof(uint32_t)); /* can be misaligned, thus memcpy */
|
||||
itag = ntohl(itag);
|
||||
@@ -3286,6 +3286,9 @@ static void handle_set_parameter_metadata(__attribute__((unused)) rtsp_conn_info
|
||||
vl = ntohl(vl);
|
||||
off += sizeof(uint32_t);
|
||||
|
||||
if (vl > cl - off)
|
||||
break;
|
||||
|
||||
// pass the data over
|
||||
if (vl == 0)
|
||||
send_metadata('core', itag, NULL, 0, NULL, 1);
|
||||
|
||||
Reference in New Issue
Block a user