Merge commit from fork

CVE-2025-68670
This commit is contained in:
metalefty
2026-01-27 18:17:29 +09:00
committed by GitHub
+10 -8
View File
@@ -305,7 +305,8 @@ xrdp_wm_ok_clicked(struct xrdp_bitmap *wnd)
*/ */
static int static int
xrdp_wm_parse_domain_information(char *originalDomainInfo, int comboMax, xrdp_wm_parse_domain_information(char *originalDomainInfo, int comboMax,
int decode, char *resultBuffer) int decode,
char *resultBuffer, unsigned int resultSize)
{ {
int ret; int ret;
int pos; int pos;
@@ -315,8 +316,7 @@ xrdp_wm_parse_domain_information(char *originalDomainInfo, int comboMax,
/* If the first char in the domain name is '_' we use the domain /* If the first char in the domain name is '_' we use the domain
name as IP*/ name as IP*/
ret = 0; /* default return value */ ret = 0; /* default return value */
/* resultBuffer assumed to be 256 chars */ g_memset(resultBuffer, 0, resultSize);
g_memset(resultBuffer, 0, 256);
if (originalDomainInfo[0] == '_') if (originalDomainInfo[0] == '_')
{ {
/* we try to locate a number indicating what combobox index the user /* we try to locate a number indicating what combobox index the user
@@ -326,7 +326,7 @@ xrdp_wm_parse_domain_information(char *originalDomainInfo, int comboMax,
* Invalid chars are ignored in microsoft client therefore we use '_' * Invalid chars are ignored in microsoft client therefore we use '_'
* again. this sec '__' contains the split for index.*/ * again. this sec '__' contains the split for index.*/
pos = g_pos(&originalDomainInfo[1], "__"); pos = g_pos(&originalDomainInfo[1], "__");
if (pos > 0) if (pos > 0 && (unsigned int)pos < resultSize)
{ {
/* an index is found we try to use it */ /* an index is found we try to use it */
LOG(LOG_LEVEL_DEBUG, "domain contains index char __"); LOG(LOG_LEVEL_DEBUG, "domain contains index char __");
@@ -348,12 +348,12 @@ xrdp_wm_parse_domain_information(char *originalDomainInfo, int comboMax,
} }
} }
/* pos limit the String to only contain the IP */ /* pos limit the String to only contain the IP */
g_strncpy(resultBuffer, &originalDomainInfo[1], pos); strlcpy(resultBuffer, &originalDomainInfo[1], pos + 1);
} }
else else
{ {
LOG(LOG_LEVEL_DEBUG, "domain does not contain _"); LOG(LOG_LEVEL_DEBUG, "domain does not contain _");
g_strncpy(resultBuffer, &originalDomainInfo[1], 255); strlcpy(resultBuffer, &originalDomainInfo[1], resultSize);
} }
} }
return ret; return ret;
@@ -486,7 +486,8 @@ xrdp_wm_show_edits(struct xrdp_wm *self, struct xrdp_bitmap *combo)
{ {
xrdp_wm_parse_domain_information( xrdp_wm_parse_domain_information(
self->session->client_info->domain, self->session->client_info->domain,
combo->data_list->count, 0, resultIP); combo->data_list->count, 0,
resultIP, sizeof(resultIP));
g_strncpy(b->caption1, resultIP, 255); g_strncpy(b->caption1, resultIP, 255);
b->edit_pos = utf8_char_count(b->caption1); b->edit_pos = utf8_char_count(b->caption1);
} }
@@ -1001,7 +1002,8 @@ xrdp_login_wnd_create(struct xrdp_wm *self)
combo->item_index = xrdp_wm_parse_domain_information( combo->item_index = xrdp_wm_parse_domain_information(
self->session->client_info->domain, self->session->client_info->domain,
combo->data_list->count, 1, combo->data_list->count, 1,
resultIP /* just a dummy place holder, we ignore */ ); resultIP,/* just a dummy place holder, we ignore */
sizeof(resultIP));
xrdp_wm_show_edits(self, combo); xrdp_wm_show_edits(self, combo);
return 0; return 0;