Linux bluetooth development
 help / color / mirror / Atom feed
* [PATCH BlueZ] Fix memory corruption when decoding Read Response PDU
@ 2011-09-28 19:01 Anderson Lizardo
  2011-10-03  8:51 ` Johan Hedberg
  0 siblings, 1 reply; 4+ messages in thread
From: Anderson Lizardo @ 2011-09-28 19:01 UTC (permalink / raw)
  To: linux-bluetooth; +Cc: Anderson Lizardo

A bogus (or hostile) Proximity Reporter device may send a TX Power value
bigger than the buffer used. Therefore, create a temporary buffer with
the maximum size, and check for the length before using the value.

Note that all other current users of the dec_read_resp() already do
this. Another option would be to change dec_read_resp() to accept a
buffer length, but this would break external code, so it is avoided for
now.
---
 proximity/monitor.c |   11 ++++++++---
 1 files changed, 8 insertions(+), 3 deletions(-)

diff --git a/proximity/monitor.c b/proximity/monitor.c
index 0ce48db..884e66d 100644
--- a/proximity/monitor.c
+++ b/proximity/monitor.c
@@ -186,7 +186,7 @@ static int write_alert_level(struct monitor *monitor)
 static void tx_power_read_cb(guint8 status, const guint8 *pdu, guint16 plen,
 							gpointer user_data)
 {
-	uint8_t value;
+	uint8_t value[ATT_MAX_MTU];
 	int vlen;
 
 	if (status != 0) {
@@ -194,12 +194,17 @@ static void tx_power_read_cb(guint8 status, const guint8 *pdu, guint16 plen,
 		return;
 	}
 
-	if (!dec_read_resp(pdu, plen, &value, &vlen)) {
+	if (!dec_read_resp(pdu, plen, value, &vlen)) {
 		DBG("Protocol error");
 		return;
 	}
 
-	DBG("Tx Power Level: %02x", (int8_t) value);
+	if (vlen != 1) {
+		DBG("Invalid length for TX Power value: %d", vlen);
+		return;
+	}
+
+	DBG("Tx Power Level: %02x", (int8_t) value[0]);
 }
 
 static void tx_power_handle_cb(GSList *characteristics, guint8 status,
-- 
1.7.0.4


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2011-10-05 10:32 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-09-28 19:01 [PATCH BlueZ] Fix memory corruption when decoding Read Response PDU Anderson Lizardo
2011-10-03  8:51 ` Johan Hedberg
2011-10-03 22:59   ` Anderson Lizardo
2011-10-05 10:32     ` Johan Hedberg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox