Commit c940cc8b authored by Matthieu Herrb's avatar Matthieu Herrb
Browse files

Fix XIChangeHierarchy() integer underflow



CVE-2020-14346 / ZDI-CAN-11429

This vulnerability was discovered by:
Jan-Niklas Sohn working with Trend Micro Zero Day Initiative
Signed-off-by: Matthieu Herrb's avatarMatthieu Herrb <matthieu@herrb.eu>
parent f7cd1276
...@@ -423,7 +423,7 @@ ProcXIChangeHierarchy(ClientPtr client) ...@@ -423,7 +423,7 @@ ProcXIChangeHierarchy(ClientPtr client)
if (!stuff->num_changes) if (!stuff->num_changes)
return rc; return rc;
len = ((size_t)stuff->length << 2) - sizeof(xXIChangeHierarchyReq); len = ((size_t)client->req_len << 2) - sizeof(xXIChangeHierarchyReq);
any = (xXIAnyHierarchyChangeInfo *) &stuff[1]; any = (xXIAnyHierarchyChangeInfo *) &stuff[1];
while (stuff->num_changes--) { while (stuff->num_changes--) {
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment