diff options
author | Nick Mathewson <nickm@torproject.org> | 2018-06-08 10:11:57 -0400 |
---|---|---|
committer | Nick Mathewson <nickm@torproject.org> | 2018-06-08 10:11:57 -0400 |
commit | c27bb4072ca25b154e100158f819315bd8683ce0 (patch) | |
tree | 2cf2f178742ccf15b145feef4d02bc5f4bd3a75a | |
parent | fa1890e97f19a444f8103c1207d7d18c02887b1f (diff) | |
parent | dd63033fcbb960ac563a8f417a7f65e62781d9a9 (diff) | |
download | tor-c27bb4072ca25b154e100158f819315bd8683ce0.tar.gz tor-c27bb4072ca25b154e100158f819315bd8683ce0.zip |
Merge branch 'maint-0.3.2' into maint-0.3.3
-rw-r--r-- | changes/bug26196 | 4 | ||||
-rw-r--r-- | src/or/protover.c | 13 |
2 files changed, 17 insertions, 0 deletions
diff --git a/changes/bug26196 b/changes/bug26196 new file mode 100644 index 0000000000..47fcffa0f8 --- /dev/null +++ b/changes/bug26196 @@ -0,0 +1,4 @@ + o Minor bugfixes (hardening): + - Prevent a possible out-of-bounds smartlist read in + protover_compute_vote(). Fixes bug 26196; bugfix on + 0.2.9.4-alpha. diff --git a/src/or/protover.c b/src/or/protover.c index 674bb1c843..b2ec3372c9 100644 --- a/src/or/protover.c +++ b/src/or/protover.c @@ -529,6 +529,10 @@ cmp_single_ent_by_version(const void **a_, const void **b_) static char * contract_protocol_list(const smartlist_t *proto_strings) { + if (smartlist_len(proto_strings) == 0) { + return tor_strdup(""); + } + // map from name to list of single-version entries strmap_t *entry_lists_by_name = strmap_new(); // list of protocol names @@ -637,6 +641,10 @@ char * protover_compute_vote(const smartlist_t *list_of_proto_strings, int threshold) { + if (smartlist_len(list_of_proto_strings) == 0) { + return tor_strdup(""); + } + smartlist_t *all_entries = smartlist_new(); // First, parse the inputs and break them into singleton entries. @@ -663,6 +671,11 @@ protover_compute_vote(const smartlist_t *list_of_proto_strings, smartlist_free(unexpanded); } SMARTLIST_FOREACH_END(vote); + if (smartlist_len(all_entries) == 0) { + smartlist_free(all_entries); + return tor_strdup(""); + } + // Now sort the singleton entries smartlist_sort_strings(all_entries); |