ddea3574a6
dchdr->dlen is a short variable controlled by the user-provided data. If the value is negative, loop continues, also increasing the value of "len". As a result buffer overflow occurs. So define the len as unsigned and check with length of string input from user space. Change-Id: I8bb9ab33d543c826eb330e16ae116385d823ca98 Signed-off-by: Raghavendra Ambadas <rambad@codeaurora.org> |
||
---|---|---|
.. | ||
mdss | ||
msm_dba | ||
vidc | ||
Kconfig | ||
Makefile | ||
mddi.c | ||
mddi_client_dummy.c | ||
mddi_client_nt35399.c | ||
mddi_client_toshiba.c | ||
mddi_hw.h | ||
mdp.c | ||
mdp_csc_table.h | ||
mdp_hw.h | ||
mdp_ppp.c | ||
mdp_scale_tables.c | ||
mdp_scale_tables.h | ||
msm_fb.c |