| 415 | } |
| 416 | |
| 417 | bool CECTag::ReadFromSocket(CECSocket& socket) |
| 418 | { |
| 419 | ec_tagname_t tmp_tagName; |
| 420 | if (!socket.ReadNumber(&tmp_tagName, sizeof(ec_tagname_t))) { |
| 421 | return false; |
| 422 | } |
| 423 | m_tagName = tmp_tagName >> 1; |
| 424 | bool hasChildren = (tmp_tagName & 0x01) != 0; |
| 425 | |
| 426 | if (!socket.ReadNumber(&m_dataType, sizeof(ec_tagtype_t))) { |
| 427 | return false; |
| 428 | } |
| 429 | |
| 430 | if (!socket.ReadNumber(&m_dataLen, sizeof(ec_taglen_t))) { |
| 431 | return false; |
| 432 | } |
| 433 | |
| 434 | if (hasChildren && !ReadChildren(socket)) { |
| 435 | return false; |
| 436 | } |
| 437 | |
| 438 | unsigned int tmp_len = m_dataLen; |
| 439 | m_dataLen = 0; |
| 440 | const bool useLargeCount = (socket.m_rx_flags & EC_FLAG_LARGE_TAG_COUNT) != 0; |
| 441 | const uint32_t childrenLen = GetTagLen(useLargeCount); |
| 442 | // Reject malformed tags whose declared length is smaller than the |
| 443 | // serialized size of the children we just parsed. Without this guard |
| 444 | // the unsigned subtraction below wraps to ~4 GB and drives an |
| 445 | // attacker-controlled oversized allocation in NewData(). |
| 446 | if (tmp_len < childrenLen) { |
| 447 | return false; |
| 448 | } |
| 449 | m_dataLen = tmp_len - childrenLen; |
| 450 | if (m_dataLen > 0) { |
| 451 | NewData(); |
| 452 | if (!socket.ReadBuffer(m_tagData, m_dataLen)) { |
| 453 | return false; |
| 454 | } |
| 455 | } else { |
| 456 | m_tagData = NULL; |
| 457 | } |
| 458 | |
| 459 | return true; |
| 460 | } |
| 461 | |
| 462 | |
| 463 | bool CECTag::WriteTag(CECSocket& socket) const |
no test coverage detected