23 lines
643 B
Diff
23 lines
643 B
Diff
From 69ad3c902ea4bbf9f21ab1857d8923f975dc6145 Mon Sep 17 00:00:00 2001
|
|
From: Aki Tuomi <aki.tuomi@open-xchange.com>
|
|
Date: Wed, 6 May 2020 13:40:36 +0300
|
|
Subject: [PATCH] auth: mech-rpa - Fail on zero len buffer
|
|
|
|
---
|
|
src/auth/mech-rpa.c | 2 +-
|
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
|
diff --git a/src/auth/mech-rpa.c b/src/auth/mech-rpa.c
|
|
index 08298ebdd6..2de8705b4f 100644
|
|
--- a/src/auth/mech-rpa.c
|
|
+++ b/src/auth/mech-rpa.c
|
|
@@ -224,7 +224,7 @@ rpa_read_buffer(pool_t pool, const unsigned char **data,
|
|
return 0;
|
|
|
|
len = *p++;
|
|
- if (p + len > end)
|
|
+ if (p + len > end || len == 0)
|
|
return 0;
|
|
|
|
*buffer = p_malloc(pool, len);
|