slirp: check data length while emulating ident function
While emulating identification protocol, tcp_emu() does not check available space in the 'sc_rcv->sb_data' buffer. It could lead to heap buffer overflow issue. Add check to avoid it. Reported-by: NKira <864786842@qq.com> Signed-off-by: NPrasad J Pandit <pjp@fedoraproject.org> Signed-off-by: NSamuel Thibault <samuel.thibault@ens-lyon.org> (cherry picked from commit a7104eda) *CVE-2019-6778 Signed-off-by: NMichael Roth <mdroth@linux.vnet.ibm.com>
Showing
想要评论请 注册 或 登录