diff options
author | José Antonio Santos Cadenas <jcaden@libresoft.es> | 2010-04-28 12:08:35 +0200 |
---|---|---|
committer | Johan Hedberg <johan.hedberg@nokia.com> | 2010-04-28 22:47:59 +0300 |
commit | 1d1154156df28660e41031df5c3f1ffe91c01aae (patch) | |
tree | d665c53659ec2641f4aef7517946dd158a2b1b57 | |
parent | 5261de27f3d5463febf4d7dfa3a7e417ba0d4df5 (diff) | |
download | bluez-1d1154156df28660e41031df5c3f1ffe91c01aae.tar.gz |
Fix list parsing bug in sdp_set_supp_features
When the data is a string or a sequence, it is not ok to dereference
data->val because it is already a pointer. Additionally a lengths
variable is added because the strings are not terminated with '\0' and
otherwise it would not be possible to know their length.
-rw-r--r-- | lib/sdp.c | 33 |
1 files changed, 31 insertions, 2 deletions
@@ -4709,6 +4709,7 @@ int sdp_set_supp_feat(sdp_record_t *rec, const sdp_list_t *sf) for (p = sf, i = 0; p; p = p->next, i++) { int plen, j; void **dtds, **vals; + int *lengths; plen = sdp_list_len(p->data); dtds = malloc(plen * sizeof(void *)); @@ -4719,14 +4720,42 @@ int sdp_set_supp_feat(sdp_record_t *rec, const sdp_list_t *sf) free(dtds); goto fail; } + lengths = malloc(plen * sizeof(int *)); + if (!lengths) { + free(dtds); + free(vals); + goto fail; + } for (r = p->data, j = 0; r; r = r->next, j++) { sdp_data_t *data = (sdp_data_t*)r->data; dtds[j] = &data->dtd; - vals[j] = &data->val; + switch (data->dtd) { + case SDP_URL_STR8: + case SDP_URL_STR16: + case SDP_TEXT_STR8: + case SDP_TEXT_STR16: + vals[j] = data->val.str; + lengths[j] = data->unitSize - sizeof(uint8_t); + break; + case SDP_ALT8: + case SDP_ALT16: + case SDP_ALT32: + case SDP_SEQ8: + case SDP_SEQ16: + case SDP_SEQ32: + vals[j] = data->val.dataseq; + lengths[j] = 0; + break; + default: + vals[j] = &data->val; + lengths[j] = 0; + break; + } } - feat = sdp_seq_alloc(dtds, vals, plen); + feat = sdp_seq_alloc_with_length(dtds, vals, lengths, plen); free(dtds); free(vals); + free(lengths); if (!feat) goto fail; seqDTDs[i] = &feat->dtd; |