Merge commit from fork
CVE-2026-41252: lib_palette_update Heap Buffer Overflow
This commit is contained in:
@@ -1649,6 +1649,13 @@ lib_palette_update(struct vnc *v)
|
|||||||
in_uint8s(s, 1);
|
in_uint8s(s, 1);
|
||||||
in_uint16_be(s, first_color);
|
in_uint16_be(s, first_color);
|
||||||
in_uint16_be(s, num_colors);
|
in_uint16_be(s, num_colors);
|
||||||
|
if ((first_color + num_colors) > VNC_PALETTE_SIZE)
|
||||||
|
{
|
||||||
|
LOG(LOG_LEVEL_ERROR, "lib_palette_update: palette overflow");
|
||||||
|
free_stream(s);
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
|
||||||
init_stream(s, 8192);
|
init_stream(s, 8192);
|
||||||
error = trans_force_read_s(v->trans, s, num_colors * 6);
|
error = trans_force_read_s(v->trans, s, num_colors * 6);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -76,6 +76,8 @@ struct xrdp_client_info;
|
|||||||
/* Defined in vnc_clip.c */
|
/* Defined in vnc_clip.c */
|
||||||
struct vnc_clipboard_data;
|
struct vnc_clipboard_data;
|
||||||
|
|
||||||
|
#define VNC_PALETTE_SIZE 256
|
||||||
|
|
||||||
/* Defined in xrdp_client_info.h */
|
/* Defined in xrdp_client_info.h */
|
||||||
struct monitor_info;
|
struct monitor_info;
|
||||||
|
|
||||||
@@ -167,7 +169,7 @@ struct vnc
|
|||||||
int server_bpp;
|
int server_bpp;
|
||||||
char mod_name[256];
|
char mod_name[256];
|
||||||
int mod_mouse_state;
|
int mod_mouse_state;
|
||||||
int palette[256];
|
int palette[VNC_PALETTE_SIZE];
|
||||||
int vnc_desktop;
|
int vnc_desktop;
|
||||||
char username[256];
|
char username[256];
|
||||||
char password[256];
|
char password[256];
|
||||||
|
|||||||
+30
-26
@@ -298,33 +298,37 @@ port=-1
|
|||||||
#disabled_encodings_mask=0
|
#disabled_encodings_mask=0
|
||||||
|
|
||||||
; Generic VNC Proxy
|
; Generic VNC Proxy
|
||||||
; Tailor this to specific hosts and VNC instances by specifying an ip
|
; To use this, remove the '#-#' prefix from the lines below. Tailor
|
||||||
|
; the section to specific hosts and VNC instances by specifying an ip
|
||||||
; and port and setting a suitable name.
|
; and port and setting a suitable name.
|
||||||
[vnc-any]
|
; This can be used with no customisations in test environments, but
|
||||||
name=vnc-any
|
; should always be locked down to specific hosts and/or ports in
|
||||||
lib=libvnc.@lib_extension@
|
; production.
|
||||||
ip=ask
|
#-#[vnc-any]
|
||||||
port=ask5900
|
#-#name=vnc-any
|
||||||
username=na
|
#-#lib=libvnc.@lib_extension@
|
||||||
password=ask
|
#-#ip=ask
|
||||||
#pamusername=asksame
|
#-#port=ask5900
|
||||||
#pampassword=asksame
|
#-#username=na
|
||||||
#delay_ms=2000
|
#-#password=ask
|
||||||
; Use one of these to connect to a chansrv instance created outside of sesman
|
#-##pamusername=asksame
|
||||||
; (e.g. as part of an x11vnc console session). Replace 's' with the
|
#-##pampassword=asksame
|
||||||
; display string of the session, and (if applicable) 'u' with the numeric
|
#-##delay_ms=2000
|
||||||
; UID of the session.
|
#-#; Use one of these to connect to a chansrv instance created outside of sesman
|
||||||
;
|
#-#; (e.g. as part of an x11vnc console session). Replace 's' with the
|
||||||
; For compatibility, a completely numeric display string is taken to be
|
#-#; display string of the session, and (if applicable) 'u' with the numeric
|
||||||
; an X11 display number
|
#-#; UID of the session.
|
||||||
;
|
#-#;
|
||||||
; You will also need to change the value of SessionSockdirGroup in
|
#-#; For compatibility, a completely numeric display string is taken to be
|
||||||
; sesman.ini to allow xrdp to reach the chansrv instance
|
#-#; an X11 display number
|
||||||
;
|
#-#;
|
||||||
; If 'username' or 'pamusername' is set, you probably don't need to use
|
#-#; You will also need to change the value of SessionSockdirGroup in
|
||||||
; the two parameter variant with 'u'.
|
#-#; sesman.ini to allow xrdp to reach the chansrv instance
|
||||||
#chansrvport=DISPLAY(n)
|
#-#;
|
||||||
#chansrvport=DISPLAY(n,u)
|
#-#; If 'username' or 'pamusername' is set, you probably don't need to use
|
||||||
|
#-#; the two parameter variant with 'u'.
|
||||||
|
#-##chansrvport=DISPLAY(n)
|
||||||
|
#-##chansrvport=DISPLAY(n,u)
|
||||||
|
|
||||||
; Generic RDP proxy using NeutrinoRDP
|
; Generic RDP proxy using NeutrinoRDP
|
||||||
; Tailor this to specific hosts by specifying an ip and port and setting
|
; Tailor this to specific hosts by specifying an ip and port and setting
|
||||||
|
|||||||
Reference in New Issue
Block a user