• Stefy Lanza (nextime / spora )'s avatar
    Fix memory corruption in wssshd tunnel request parameter extraction · 4505d02e
    Stefy Lanza (nextime / spora ) authored
    - Added bounds checking and validation for enc, service, and version parameter extraction
    - Prevent buffer overflows by limiting parameter lengths to reasonable sizes (< 32 chars)
    - Added null pointer and bounds validation before string operations
    - Increased request_msg buffer size from 512 to 1024 bytes for safety
    - Fixed potential heap corruption that was causing 'malloc(): invalid next size' errors
    4505d02e
Name
Last commit
Last update
..
Makefile Loading commit data...
assets.c Loading commit data...
assets.h Loading commit data...
assets.o Loading commit data...
config.c Loading commit data...
config.h Loading commit data...
config.o Loading commit data...
json.h Loading commit data...
main.c Loading commit data...
main.o Loading commit data...
ssl.c Loading commit data...
ssl.h Loading commit data...
ssl.o Loading commit data...
terminal.c Loading commit data...
terminal.h Loading commit data...
terminal.o Loading commit data...
test.conf Loading commit data...
test2.conf Loading commit data...
tunnel.c Loading commit data...
tunnel.h Loading commit data...
tunnel.o Loading commit data...
web.c Loading commit data...
web.h Loading commit data...
web.o Loading commit data...
websocket.c Loading commit data...
websocket.h Loading commit data...
websocket.o Loading commit data...
websocket_protocol.c Loading commit data...
websocket_protocol.h Loading commit data...
websocket_protocol.o Loading commit data...
wssshd Loading commit data...