Bladeren bron

topoh: detect when via param is shorter than expected prefix

(cherry picked from commit e6950ffb1985493e717e3d774eddad779aed1514)
Daniel-Constantin Mierla 6 jaren geleden
bovenliggende
commit
06c6a73f05
1 gewijzigde bestanden met toevoegingen van 7 en 2 verwijderingen
  1. 7 2
      src/modules/topoh/th_msg.c

+ 7 - 2
src/modules/topoh/th_msg.c

@@ -410,12 +410,17 @@ int th_unmask_via(sip_msg_t *msg, str *cookie)
 					LM_ERR("cannot find param in via %d\n", i);
 					return -1;
 				}
-				if(i==2)
+				if(vp->value.len <= th_vparam_prefix.len) {
+					LM_ERR("invalid param len in via %d\n", i);
+					return -1;
+				}
+				if(i==2) {
 					out.s = th_mask_decode(vp->value.s, vp->value.len,
 							&th_vparam_prefix, CRLF_LEN+1, &out.len);
-				else
+				} else {
 					out.s = th_mask_decode(vp->value.s, vp->value.len,
 							&th_vparam_prefix, 0, &out.len);
+				}
 				if(out.s==NULL || out.len<=0)
 				{
 					LM_ERR("cannot decode via %d\n", i);