Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dcerpc: prevent integer underflow #12532

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

catenacyber
Copy link
Contributor

Link to ticket: https://redmine.openinfosecfoundation.org/issues/
https://redmine.openinfosecfoundation.org/issues/7548

Describe changes:

  • dcerpc: prevent integer underflow

There may be other things to do, like setting an event, but what remains to do is not clear to me.
What is clear to me is that this small change is an improvement.

First commit of #12528 with ticket

in case a fragment has a length lesser than DCERPC_HDR_LEN

Fixes: 9daf852 ("dcerpc: tidy up code")

Ticket: 7548
Copy link

codecov bot commented Feb 5, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 80.69%. Comparing base (d4330ef) to head (05fa4e5).

Additional details and impacted files
@@           Coverage Diff           @@
##           master   #12532   +/-   ##
=======================================
  Coverage   80.68%   80.69%           
=======================================
  Files         925      925           
  Lines      258914   258914           
=======================================
+ Hits       208914   208920    +6     
+ Misses      50000    49994    -6     
Flag Coverage Δ
fuzzcorpus 56.88% <100.00%> (+0.05%) ⬆️
livemode 19.41% <0.00%> (+<0.01%) ⬆️
pcap 44.19% <100.00%> (-0.01%) ⬇️
suricata-verify 63.39% <100.00%> (-0.01%) ⬇️
unittests 58.38% <100.00%> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 24627

Copy link
Member

@inashivb inashivb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀

@victorjulien victorjulien added this to the 8.0 milestone Feb 10, 2025
@inashivb
Copy link
Member

There may be other things to do, like setting an event, but what remains to do is not clear to me. What is clear to me is that this small change is an improvement.

@catenacyber could you please tell what is unclear to you?
We need to do https://redmine.openinfosecfoundation.org/issues/7254 and the related tickets that have been added by you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

4 participants