mirror of
https://github.com/signalwire/freeswitch.git
synced 2026-10-04 02:03:59 +00:00
Merge commit from fork
`switch_core_media_add_crypto()` parses the SDP `a=crypto` keysalt and decodes it into a fixed-size key buffer. Enforce the buffer contract at the call site: - Reject a zero-length, negative, or over-long keysalt (the length check now has both a lower bound and an upper bound against the copy buffer). - Copy the keysalt token into a NUL-terminated buffer and decode from that, so `switch_b64_decode` stops at the token instead of reading on into the following key material (it consumes input to the NUL and skips non-base64 bytes). - Pass the destination buffer size as the decode bound rather than the parsed token length. - Require the decoded length to cover the crypto suite's key+salt so the subsequent copy cannot read past the decoded bytes. Add `test_add_crypto_keysalt_bounds`, a table-driven test covering the accepted and rejected keysalt shapes across suites (AES-128/192/256), including RFC 4568 lifetime/MKI and multi-key lines.
This commit is contained in:
@@ -6,6 +6,7 @@ noinst_PROGRAMS += switch_core_video switch_core_db switch_vad switch_packetizer
|
||||
noinst_PROGRAMS += switch_stun
|
||||
noinst_PROGRAMS += test_tts_format
|
||||
noinst_PROGRAMS+= switch_hold switch_sip
|
||||
noinst_PROGRAMS += switch_core_media
|
||||
noinst_PROGRAMS += test_mod_verto
|
||||
noinst_PROGRAMS += test_mod_event_socket
|
||||
|
||||
|
||||
Reference in New Issue
Block a user