summaryrefslogtreecommitdiff
path: root/xserver/xfixes/region.c
diff options
context:
space:
mode:
authorMatthieu Herrb <matthieu@cvs.openbsd.org>2017-10-14 09:22:50 +0000
committerMatthieu Herrb <matthieu@cvs.openbsd.org>2017-10-14 09:22:50 +0000
commitc1c1edc23ddc3a957e8899b73bb933a2028988fb (patch)
tree4ecc6c5da9582520264eb53e2a3448c4b3dac050 /xserver/xfixes/region.c
parentef3dccc55e2d4ae4570905b59e15b660f4bb940d (diff)
MFC: xfixes: unvalidated lengths (CVE-2017-12183)
v2: Use before swap (Jeremy Huddleston Sequoia) v3: Fix wrong XFixesCopyRegion checks (Alan Coopersmith)
Diffstat (limited to 'xserver/xfixes/region.c')
-rw-r--r--xserver/xfixes/region.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/xserver/xfixes/region.c b/xserver/xfixes/region.c
index dd74d7f7e..f300d2b6e 100644
--- a/xserver/xfixes/region.c
+++ b/xserver/xfixes/region.c
@@ -359,6 +359,7 @@ ProcXFixesCopyRegion(ClientPtr client)
RegionPtr pSource, pDestination;
REQUEST(xXFixesCopyRegionReq);
+ REQUEST_SIZE_MATCH(xXFixesCopyRegionReq);
VERIFY_REGION(pSource, stuff->source, client, DixReadAccess);
VERIFY_REGION(pDestination, stuff->destination, client, DixWriteAccess);
@@ -375,7 +376,7 @@ SProcXFixesCopyRegion(ClientPtr client)
REQUEST(xXFixesCopyRegionReq);
swaps(&stuff->length);
- REQUEST_AT_LEAST_SIZE(xXFixesCopyRegionReq);
+ REQUEST_SIZE_MATCH(xXFixesCopyRegionReq);
swapl(&stuff->source);
swapl(&stuff->destination);
return (*ProcXFixesVector[stuff->xfixesReqType]) (client);