Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(677)

Unified Diff: webrtc/modules/rtp_rtcp/source/rtp_packet.cc

Issue 2327743003: Fix oversized rtp header extension parsing. (Closed)
Patch Set: Fix + nits nearby Created 4 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | webrtc/modules/rtp_rtcp/source/rtp_packet_unittest.cc » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: webrtc/modules/rtp_rtcp/source/rtp_packet.cc
diff --git a/webrtc/modules/rtp_rtcp/source/rtp_packet.cc b/webrtc/modules/rtp_rtcp/source/rtp_packet.cc
index 8c8fa0e79ad62d47cff2dc3dfd0b6c9fc70e260e..283512cd8fa51e7d7dc74da62f5cc116f9051ad3 100644
--- a/webrtc/modules/rtp_rtcp/source/rtp_packet.cc
+++ b/webrtc/modules/rtp_rtcp/source/rtp_packet.cc
@@ -11,6 +11,7 @@
#include "webrtc/modules/rtp_rtcp/source/rtp_packet.h"
#include <cstring>
+#include <utility>
#include "webrtc/base/checks.h"
#include "webrtc/base/logging.h"
@@ -397,11 +398,16 @@ bool Packet::ParseBuffer(const uint8_t* buffer, size_t size) {
}
uint8_t length =
1 + (buffer[extension_offset + extensions_size_] & 0xf);
- extensions_size_ += kOneByteHeaderSize;
+ if (extensions_size_ + kOneByteHeaderSize + length >
+ extensions_capacity) {
+ LOG(LS_WARNING) << "Oversized rtp header extension.";
+ break;
+ }
if (num_extensions_ >= kMaxExtensionHeaders) {
- LOG(LS_WARNING) << "Too many extensions.";
- return false;
+ LOG(LS_WARNING) << "Too many rtp header extensions.";
+ break;
}
+ extensions_size_ += kOneByteHeaderSize;
extension_entries_[num_extensions_].type =
extensions_ ? extensions_->GetType(id)
: ExtensionManager::kInvalidType;
« no previous file with comments | « no previous file | webrtc/modules/rtp_rtcp/source/rtp_packet_unittest.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698