瀏覽代碼

Add missing check for hostname answer_len in dnsserv size

This is checked elsewhere too, but let's be RFC-conformant.
Nick Mathewson 14 年之前
父節點
當前提交
31b562e10a
共有 1 個文件被更改,包括 1 次插入0 次删除
  1. 1 0
      src/or/dnsserv.c

+ 1 - 0
src/or/dnsserv.c

@@ -271,6 +271,7 @@ dnsserv_resolved(edge_connection_t *conn,
                                      name,
                                      1, (char*)answer, ttl);
   } else if (answer_type == RESOLVED_TYPE_HOSTNAME &&
+             answer_len < 256 &&
              conn->socks_request->command == SOCKS_COMMAND_RESOLVE_PTR) {
     char *ans = tor_strndup(answer, answer_len);
     evdns_server_request_add_ptr_reply(req, NULL,