Explorar o código

package/swconfig: add sanity checks to prevent a segfault

SVN-Revision: 24932
Gabor Juhos %!s(int64=15) %!d(string=hai) anos
pai
achega
9a32655293
Modificáronse 2 ficheiros con 16 adicións e 1 borrados
  1. 1 1
      package/swconfig/Makefile
  2. 15 0
      package/swconfig/src/swlib.c

+ 1 - 1
package/swconfig/Makefile

@@ -8,7 +8,7 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=swconfig
-PKG_RELEASE:=6
+PKG_RELEASE:=7
 
 include $(INCLUDE_DIR)/package.mk
 include $(INCLUDE_DIR)/kernel.mk

+ 15 - 0
package/swconfig/src/swlib.c

@@ -368,11 +368,26 @@ int swlib_set_attr_string(struct switch_dev *dev, struct switch_attr *a, int por
 		ptr = (char *)str;
 		while(ptr && *ptr)
 		{
+			while(*ptr && isspace(*ptr))
+				ptr++;
+
+			if (!*ptr)
+				break;
+
+			if (!isdigit(*ptr))
+				return -1;
+
+			if (val.len >= dev->ports)
+				return -1;
+
 			ports[val.len].flags = 0;
 			ports[val.len].id = strtoul(ptr, &ptr, 10);
 			while(*ptr && !isspace(*ptr)) {
 				if (*ptr == 't')
 					ports[val.len].flags |= SWLIB_PORT_FLAG_TAGGED;
+				else
+					return -1;
+
 				ptr++;
 			}
 			if (*ptr)