diff options
| author | Christophe Fergeau <cfergeau@redhat.com> | 2014-09-09 18:00:30 +0200 |
|---|---|---|
| committer | Christophe Fergeau <cfergeau@redhat.com> | 2014-09-18 14:06:55 +0200 |
| commit | e270edcbfd958d764e84cdbca6d403ff24fef610 (patch) | |
| tree | 8d846a345b163a8e5abfa0d57c1656f7c3c4629d /client/client_net_socket.cpp | |
| parent | 2cc42d9358effcac325e63fd2b42766a771bf1bf (diff) | |
Validate surface bounding box before using it
It's possible for a buggy guest driver to pass invalid bounding box
dimensions in QXL commands, which would then cause spice-server to
segfault. This patch checks the size of the bounding box of the QXL
command right after it has been parsed.
This fixes rhbz#1135372
Diffstat (limited to 'client/client_net_socket.cpp')
0 files changed, 0 insertions, 0 deletions
