diff options
| author | liuxueli <[email protected]> | 2021-11-10 19:34:24 +0300 |
|---|---|---|
| committer | liuxueli <[email protected]> | 2021-11-10 19:34:24 +0300 |
| commit | 27f6517fd3d281589dd3ac58d3d2cc2f360bd82a (patch) | |
| tree | c50c927aab821c50de835615e94d765cbdc9227d | |
| parent | 88c426204b11a05a4e452647c3fed9e736286051 (diff) | |
TSG-8210: 增加对server hello extension字段的长度进行判断,避免处理异常时出现memcpy越界v2.0.6
| -rw-r--r-- | src/SSL_Message.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/src/SSL_Message.c b/src/SSL_Message.c index b259797..c4942f8 100644 --- a/src/SSL_Message.c +++ b/src/SSL_Message.c @@ -478,7 +478,7 @@ UCHAR ssl_analyseHandShake(char *pcSslData, int iAllMsgLen, int iSslUnAnalyseL a_ssl_stream->stServerHello->exts[i].len = (unsigned short)BtoL2BytesNum(pcCurSslData); pcCurSslData += sizeof(a_ssl_stream->stServerHello->exts[i].len); iUnAnaHelloLen -= sizeof(a_ssl_stream->stServerHello->exts[i].len); - if(iUnAnaHelloLen<0) + if(iUnAnaHelloLen<0 || a_ssl_stream->stServerHello->exts[i].len>iUnAnaHelloLen) { return SSL_RETURN_DROPME; } |
