gnunet-svn
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[taler-exchange] branch master updated: enforce proper URL limit (#6172)


From: gnunet
Subject: [taler-exchange] branch master updated: enforce proper URL limit (#6172)
Date: Thu, 09 Apr 2020 15:49:41 +0200

This is an automated email from the git hooks/post-receive script.

grothoff pushed a commit to branch master
in repository exchange.

The following commit(s) were added to refs/heads/master by this push:
     new dccb300b enforce proper URL limit (#6172)
dccb300b is described below

commit dccb300b76fbf35ced3bb6b8becbfc2ba98407cc
Author: Christian Grothoff <address@hidden>
AuthorDate: Thu Apr 9 15:49:29 2020 +0200

    enforce proper URL limit (#6172)
---
 src/bank-lib/bank_api_transfer.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/src/bank-lib/bank_api_transfer.c b/src/bank-lib/bank_api_transfer.c
index 0cf59602..5ec74760 100644
--- a/src/bank-lib/bank_api_transfer.c
+++ b/src/bank-lib/bank_api_transfer.c
@@ -91,8 +91,9 @@ TALER_BANK_prepare_transfer (
   size_t u_len = strlen (exchange_base_url) + 1;
   char *end;
 
-  if ( (d_len > (size_t) UINT32_MAX) ||
-       (u_len > (size_t) UINT32_MAX) )
+  if ( (d_len >= (size_t) GNUNET_MAX_MALLOC_CHECKED) ||
+       (u_len >= (size_t) GNUNET_MAX_MALLOC_CHECKED) ||
+       (d_len + u_len + sizeof (*wp) >= GNUNET_MAX_MALLOC_CHECKED) )
   {
     GNUNET_break (0); /* that's some long URL... */
     *buf = NULL;

-- 
To stop receiving notification emails like this one, please contact
address@hidden.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]