Thread (11 messages) flat view 11 messages, 2 authors, 2014-02-28

Re: [PATCHv2 4/9] avrcp: Fix buffer size check

From: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Date: 2014-02-28 14:26:27

Hi Andrei,

On Fri, Feb 28, 2014 at 3:18 PM, Andrei Emeltchenko
[off-list ref] wrote:
quoted hunk ↗ jump to hunk
From: Andrei Emeltchenko <redacted>

Fix size check taking into account that attributes starts from 1 (0 is
illegal).
---
 profiles/audio/avrcp.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/profiles/audio/avrcp.c b/profiles/audio/avrcp.c
index c0e5d07..48c3355 100644
--- a/profiles/audio/avrcp.c
+++ b/profiles/audio/avrcp.c
@@ -1909,7 +1909,7 @@ static void avrcp_get_current_player_value(struct avrcp *session,
        struct avrcp_header *pdu = (void *) buf;
        uint16_t length = AVRCP_HEADER_LENGTH + count + 1;

-       if (count > AVRCP_ATTRIBUTE_LAST + 1)
+       if (count > AVRCP_ATTRIBUTE_LAST)
                return;

        memset(buf, 0, sizeof(buf));
--
1.8.3.2
This does not apply anymore, there is no check inside
avrcp_get_current_player_value.


-- 
Luiz Augusto von Dentz
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help