diff options
-rw-r--r-- | ChangeLog | 1 | ||||
-rw-r--r-- | src/sync-mode.c | 5 |
2 files changed, 6 insertions, 0 deletions
@@ -93,6 +93,7 @@ o remove init_alarm() before add_alarm() o fix error checking of local_create_server() o added struct local_server, several cleanups in local socket infrastructure o remove unused prototypes in network.h +o check if the received packet is large enough version 0.9.5 (2007/07/29) ------------------------------ diff --git a/src/sync-mode.c b/src/sync-mode.c index 4f7833c..f726272 100644 --- a/src/sync-mode.c +++ b/src/sync-mode.c @@ -99,6 +99,11 @@ static void mcast_handler(void) while (remain > 0) { struct nethdr *net = (struct nethdr *) ptr; + if (remain < NETHDR_SIZ) { + STATE(malformed)++; + break; + } + if (ntohs(net->len) > remain) { dlog(LOG_ERR, "fragmented messages"); break; |