summaryrefslogtreecommitdiffstats
path: root/common
diff options
context:
space:
mode:
authorJay Sorg <jay.sorg@gmail.com>2013-09-10 16:00:30 -0700
committerJay Sorg <jay.sorg@gmail.com>2013-09-10 16:00:30 -0700
commit39ed446e1513c52f795d090fc9b1f173c0912d6a (patch)
tree6e47fae59fd77f52b44fa3d1bf51871152e9a363 /common
parent4e58a5a3c022f90ce9219e126893b721fee2b90a (diff)
downloadxrdp-proprietary-39ed446e1513c52f795d090fc9b1f173c0912d6a.tar.gz
xrdp-proprietary-39ed446e1513c52f795d090fc9b1f173c0912d6a.zip
VUL: fix some possible buffer overruns
Diffstat (limited to 'common')
-rw-r--r--common/parse.h3
-rw-r--r--common/trans.c6
2 files changed, 8 insertions, 1 deletions
diff --git a/common/parse.h b/common/parse.h
index 3ec37104..69a57ff8 100644
--- a/common/parse.h
+++ b/common/parse.h
@@ -56,6 +56,9 @@ struct stream
#define s_check_rem(s, n) ((s)->p + (n) <= (s)->end)
/******************************************************************************/
+#define s_check_rem_out(s, n) ((s)->p + (n) <= (s)->data + (s)->size)
+
+/******************************************************************************/
#define s_check_end(s) ((s)->p == (s)->end)
/******************************************************************************/
diff --git a/common/trans.c b/common/trans.c
index 0b672168..8313b606 100644
--- a/common/trans.c
+++ b/common/trans.c
@@ -221,8 +221,12 @@ trans_force_read_s(struct trans *self, struct stream *in_s, int size)
while (size > 0)
{
+ /* make sure stream has room */
+ if ((in_s->end + size) > (in_s->data + in_s->size))
+ {
+ return 1;
+ }
rcvd = g_tcp_recv(self->sck, in_s->end, size, 0);
-
if (rcvd == -1)
{
if (g_tcp_last_error_would_block(self->sck))