Misc code cleanups arising from Google analysis.

No security impleications or CVEs.
This commit is contained in:
Simon Kelley
2017-09-25 20:19:55 +01:00
parent 51eadb692a
commit 6a0b00f0d6
3 changed files with 5 additions and 3 deletions

View File

@@ -159,7 +159,7 @@ size_t add_pseudoheader(struct dns_header *header, size_t plen, unsigned char *l
/* delete option if we're to replace it. */ /* delete option if we're to replace it. */
p -= 4; p -= 4;
rdlen -= len + 4; rdlen -= len + 4;
memcpy(p, p+len+4, rdlen - i); memmove(p, p+len+4, rdlen - i);
PUTSHORT(rdlen, lenp); PUTSHORT(rdlen, lenp);
lenp -= 2; lenp -= 2;
} }

View File

@@ -37,7 +37,7 @@ int extract_name(struct dns_header *header, size_t plen, unsigned char **pp,
/* end marker */ /* end marker */
{ {
/* check that there are the correct no of bytes after the name */ /* check that there are the correct no of bytes after the name */
if (!CHECK_LEN(header, p, plen, extrabytes)) if (!CHECK_LEN(header, p1 ? p1 : p, plen, extrabytes))
return 0; return 0;
if (isExtract) if (isExtract)
@@ -498,6 +498,8 @@ static unsigned char *do_doctor(unsigned char *p, int count, struct dns_header *
{ {
unsigned int i, len = *p1; unsigned int i, len = *p1;
unsigned char *p2 = p1; unsigned char *p2 = p1;
if ((p1 + len - p) >= rdlen)
return 0; /* bad packet */
/* make counted string zero-term and sanitise */ /* make counted string zero-term and sanitise */
for (i = 0; i < len; i++) for (i = 0; i < len; i++)
{ {

View File

@@ -157,7 +157,7 @@ size_t dhcp_reply(struct dhcp_context *context, char *iface_name, int int_index,
for (offset = 0; offset < (len - 5); offset += elen + 5) for (offset = 0; offset < (len - 5); offset += elen + 5)
{ {
elen = option_uint(opt, offset + 4 , 1); elen = option_uint(opt, offset + 4 , 1);
if (option_uint(opt, offset, 4) == BRDBAND_FORUM_IANA) if (option_uint(opt, offset, 4) == BRDBAND_FORUM_IANA && offset + elen + 5 <= len)
{ {
unsigned char *x = option_ptr(opt, offset + 5); unsigned char *x = option_ptr(opt, offset + 5);
unsigned char *y = option_ptr(opt, offset + elen + 5); unsigned char *y = option_ptr(opt, offset + elen + 5);