forked from Mirrors/freeswitch
add bounds checking
git-svn-id: http://svn.freeswitch.org/svn/freeswitch/trunk@7262 d0543943-73ff-0310-b7d9-9358b9ac24b2
This commit is contained in:
parent
7cc21a90bd
commit
80d137165d
@ -491,12 +491,15 @@ SWITCH_DECLARE(switch_status_t) switch_rtp_add_crypto_key(switch_rtp_t *rtp_sess
|
||||
unsigned char *key,
|
||||
switch_size_t keylen)
|
||||
{
|
||||
|
||||
switch_rtp_crypto_key_t *crypto_key;
|
||||
srtp_policy_t *policy;
|
||||
err_status_t stat;
|
||||
switch_status_t status = SWITCH_STATUS_SUCCESS;
|
||||
|
||||
if (direction >= SWITCH_RTP_CRYPTO_MAX || keylen > SWITCH_RTP_MAX_CRYPTO_LEN) {
|
||||
return SWITCH_STATUS_FALSE;
|
||||
}
|
||||
|
||||
crypto_key = switch_core_alloc(rtp_session->pool, sizeof(*crypto_key));
|
||||
|
||||
if (direction == SWITCH_RTP_CRYPTO_RECV) {
|
||||
@ -505,17 +508,14 @@ SWITCH_DECLARE(switch_status_t) switch_rtp_add_crypto_key(switch_rtp_t *rtp_sess
|
||||
policy = &rtp_session->send_policy;
|
||||
}
|
||||
|
||||
|
||||
crypto_key->type = type;
|
||||
crypto_key->index = index;
|
||||
memcpy(crypto_key->key, key, keylen);
|
||||
crypto_key->next = rtp_session->crypto_keys[direction];
|
||||
rtp_session->crypto_keys[direction] = crypto_key;
|
||||
|
||||
|
||||
memset(policy, 0, sizeof(*policy));
|
||||
|
||||
|
||||
switch(crypto_key->type) {
|
||||
case AES_CM_128_HMAC_SHA1_80:
|
||||
crypto_policy_set_aes_cm_128_hmac_sha1_80(&policy->rtp);
|
||||
@ -527,7 +527,6 @@ SWITCH_DECLARE(switch_status_t) switch_rtp_add_crypto_key(switch_rtp_t *rtp_sess
|
||||
break;
|
||||
}
|
||||
|
||||
|
||||
policy->next = NULL;
|
||||
policy->key = (uint8_t *) crypto_key->key;
|
||||
crypto_policy_set_rtcp_default(&policy->rtcp);
|
||||
@ -581,9 +580,9 @@ SWITCH_DECLARE(switch_status_t) switch_rtp_add_crypto_key(switch_rtp_t *rtp_sess
|
||||
}
|
||||
|
||||
return SWITCH_STATUS_SUCCESS;
|
||||
|
||||
}
|
||||
|
||||
|
||||
SWITCH_DECLARE(switch_status_t) switch_rtp_create(switch_rtp_t **new_rtp_session,
|
||||
switch_payload_t payload,
|
||||
uint32_t samples_per_interval,
|
||||
|
Loading…
Reference in New Issue
Block a user