#10536 closed defect (fixed)

extend_cell_parse: don't try to parse payload if zero length

Priority: Medium Milestone: Tor: 0.2.5.x-final
Component: Core Tor/Tor Version:
If payload length for EXTEND2 cell is zero then extend_cell_parse() still tries to parse it by:

uint8_t n_specs = *payload

This bug should be harmless as

 if (eop - payload < 2)

still true.

Fixed code should be looking like:

uint8_t n_specs = 0;
if (eop - payload > 0)


uint8_t n_specs;
if (eop - payload < 1)
  return -1;
cell_out->cell_type = RELAY_COMMAND_EXTEND2;

or like dropping cell for any cell type if zero length.

extend_cell_parse(extend_cell_t *cell_out, const uint8_t command,
                  const uint8_t *payload, size_t payload_length)
  const uint8_t *eop;

  memset(cell_out, 0, sizeof(*cell_out));
  if (payload_length > RELAY_PAYLOAD_SIZE || 0 == payload_length)
    return -1;

or something.

comment:1 Changed 7 years ago by nickm

Milestone: Tor: 0.2.5.x-final
Resolution: fixed
Status: newclosed

Fixed in 90303602773eca8505229c832119dafcbcfe1ab7

comment:2 Changed 7 years ago by cypherpunks

Fixed in

