From c445c434226a5d0d899d9761b19b6fa9ca6244fc Mon Sep 17 00:00:00 2001 From: aled-ua Date: Tue, 24 Dec 2024 07:56:22 +0000 Subject: [PATCH] Fix vuln OSV-2023-1150 --- Packet++/src/PacketUtils.cpp | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/Packet++/src/PacketUtils.cpp b/Packet++/src/PacketUtils.cpp index fda7a9bc40..950320198f 100644 --- a/Packet++/src/PacketUtils.cpp +++ b/Packet++/src/PacketUtils.cpp @@ -17,6 +17,11 @@ namespace pcpp uint32_t localSum = 0; // vec len is in bytes + if (vec[i].len > sizeof(vec[i].buffer)) + { + PCPP_LOG_ERROR("Buffer overflow detected: vec[i].len exceeds buffer size"); + return 0; // Return an invalid checksum + } for (size_t j = 0; j < vec[i].len / 2; j++) { PCPP_LOG_DEBUG("Value to add = 0x" << std::uppercase << std::hex << vec[i].buffer[j]);