fix: Check options array is always an even size

This commit is contained in:
sithlord48 2026-06-30 08:29:58 -04:00 committed by Nick Bolton
parent 570e68e910
commit 8266fbbe6a
5 changed files with 24 additions and 0 deletions

View file

@ -301,6 +301,11 @@ void Client::resetOptions()
void Client::setOptions(const OptionsList &options) void Client::setOptions(const OptionsList &options)
{ {
if (options.size() % 2 != 0) {
LOG_ERR("options are the incorrect size, can not process them");
return;
}
for (auto index = options.begin(); index != options.end(); ++index) { for (auto index = options.begin(); index != options.end(); ++index) {
const OptionID id = *index; const OptionID id = *index;
if (id == kOptionClipboardSharing) { if (id == kOptionClipboardSharing) {

View file

@ -773,6 +773,11 @@ void ServerProxy::setOptions()
ProtocolUtil::readf(m_stream, kMsgDSetOptions + 4, &options); ProtocolUtil::readf(m_stream, kMsgDSetOptions + 4, &options);
LOG_VERBOSE("recv set options size=%d", options.size()); LOG_VERBOSE("recv set options size=%d", options.size());
if (options.size() % 2 != 0) {
LOG_ERR("options are the incorrect size, can not process them");
return;
}
// forward // forward
m_client->setOptions(options); m_client->setOptions(options);

View file

@ -281,6 +281,11 @@ void Screen::resetOptions()
void Screen::setOptions(const OptionsList &options) void Screen::setOptions(const OptionsList &options)
{ {
if (options.size() % 2 != 0) {
LOG_ERR("options are the incorrect size, can not process them");
return;
}
// update options // update options
for (uint32_t i = 0, n = (uint32_t)options.size(); i < n; i += 2) { for (uint32_t i = 0, n = (uint32_t)options.size(); i < n; i += 2) {
if (options[i] == kOptionHalfDuplexCapsLock) { if (options[i] == kOptionHalfDuplexCapsLock) {

View file

@ -400,6 +400,10 @@ void XWindowsScreen::resetOptions()
void XWindowsScreen::setOptions(const OptionsList &options) void XWindowsScreen::setOptions(const OptionsList &options)
{ {
if (options.size() % 2 != 0) {
LOG_ERR("options are the incorrect size, can not process them");
return;
}
for (uint32_t i = 0, n = options.size(); i < n; i += 2) { for (uint32_t i = 0, n = options.size(); i < n; i += 2) {
if (options[i] == kOptionXTestXineramaUnaware) { if (options[i] == kOptionXTestXineramaUnaware) {
m_xtestIsXineramaUnaware = (options[i + 1] != 0); m_xtestIsXineramaUnaware = (options[i + 1] != 0);

View file

@ -350,6 +350,11 @@ void ClientProxy1_0::resetOptions()
void ClientProxy1_0::setOptions(const OptionsList &options) void ClientProxy1_0::setOptions(const OptionsList &options)
{ {
LOG_VERBOSE("send set options to \"%s\" size=%d", getName().c_str(), options.size()); LOG_VERBOSE("send set options to \"%s\" size=%d", getName().c_str(), options.size());
if (options.size() % 2 != 0) {
LOG_ERR("options are the incorrect size, not sending");
return;
}
ProtocolUtil::writef(getStream(), kMsgDSetOptions, &options); ProtocolUtil::writef(getStream(), kMsgDSetOptions, &options);
// check options // check options