diff --git a/common/string_calls.c b/common/string_calls.c index 941a2995..b039c692 100644 --- a/common/string_calls.c +++ b/common/string_calls.c @@ -232,7 +232,10 @@ g_get_display_string(char buff[], unsigned int bufflen) // Return the unqualified part of the name p = strrchr(str, '/'); p = (p != NULL) ? (p + 1) : str; - strlcpy(buff, p, bufflen); + if (strlcpy(buff, p, bufflen) >= bufflen) + { + rv = -1; /* Buffer overflow */ + } } else if ((str = g_getenv("DISPLAY")) != NULL) { @@ -240,7 +243,11 @@ g_get_display_string(char buff[], unsigned int bufflen) if (n >= 0) { - g_snprintf(buff, bufflen, "X11-%d", n); + if ((unsigned int)g_snprintf(buff, bufflen, "X11-%d", n) + >= bufflen) + { + rv = -1; /* Buffer overflow */ + } } else { diff --git a/sesman/sesexec/session.c b/sesman/sesexec/session.c index 0231dfce..7d49b6fa 100644 --- a/sesman/sesexec/session.c +++ b/sesman/sesexec/session.c @@ -682,13 +682,12 @@ start_x_server(const struct login_info *login_info, g_cfg->env_names, g_cfg->env_values); - if (sp->type == SCP_SESSION_TYPE_XVNC) + /* Allocate the passwd_file if required */ + if (sp->type == SCP_SESSION_TYPE_XVNC && + (passwd_file = get_xvnc_passwd_file_name(sp->x11_display)) == NULL) { - char guid_str[GUID_STR_SIZE]; - passwd_file = get_xvnc_passwd_file_name(sp->x11_display); - - guid_to_str(&sp->guid, guid_str); - set_xvnc_passwd(passwd_file, guid_str); + /* An error has been logged */ + return; } /* prepare the Xauthority stuff */ @@ -714,6 +713,7 @@ start_x_server(const struct login_info *login_info, { switch (sp->type) { + char guid_str[GUID_STR_SIZE]; char port[256]; case SCP_SESSION_TYPE_XORG: @@ -721,6 +721,8 @@ start_x_server(const struct login_info *login_info, break; case SCP_SESSION_TYPE_XVNC: + guid_to_str(&sp->guid, guid_str); + set_xvnc_passwd(passwd_file, guid_str); xserver_params = prepare_xvnc_xserver_params(sd, authfile, passwd_file, NULL); break; diff --git a/sesman/tools/dis.c b/sesman/tools/dis.c index 76c2e0ad..9207131b 100644 --- a/sesman/tools/dis.c +++ b/sesman/tools/dis.c @@ -49,7 +49,7 @@ int main(int argc, char **argv) if (g_get_display_string(disstr, sizeof(disstr)) < 0) { - printf("Can't find teh display from the environment\n"); + printf("Can't find the display from the environment\n"); return 1; } diff --git a/xrdp/xrdp_mm.c b/xrdp/xrdp_mm.c index f1a76380..08570218 100644 --- a/xrdp/xrdp_mm.c +++ b/xrdp/xrdp_mm.c @@ -2963,7 +2963,7 @@ cleanup_states(struct xrdp_mm *self) */ static int -parse_chansrvport(const char *value, char *dest, int dest_size, int uid) +parse_chansrvport(const char *value, char dest[], int dest_size, int uid) { int rv = 0; char dstr[MAX_DISPLAY_NAME_SIZE]; @@ -3003,8 +3003,14 @@ parse_chansrvport(const char *value, char *dest, int dest_size, int uid) { // X11 compatibility int dnum = g_atoi(dstr); - (void)g_get_display_string_from_x11_display( - dnum, dstr, sizeof(dstr)); + if (g_get_display_string_from_x11_display( + dnum, dstr, sizeof(dstr)) < 0) + { + LOG(LOG_LEVEL_WARNING, + "Ignoring chansrvport string " + "with bad X11 display number '%s'", value); + return -1; + } } if (*end == ',')