diff options
author | luigi1111 <luigi1111w@gmail.com> | 2019-08-27 15:19:47 -0500 |
---|---|---|
committer | luigi1111 <luigi1111w@gmail.com> | 2019-08-27 15:19:47 -0500 |
commit | f68512e9e41fa9447508dedefe6aec94c94cf6df (patch) | |
tree | 2761cbe4d28985a59693f74a0e4eacbc998d14d3 /src/device/device_ledger.cpp | |
parent | Merge pull request #5609 (diff) | |
parent | device_ledger: fix uninitialized additional_key (diff) | |
download | monero-f68512e9e41fa9447508dedefe6aec94c94cf6df.tar.xz |
Merge pull request #5729
7c894fc device_ledger: add paranoid buffer overflow check (moneromooo-monero)
f07524b device_ledger: fix uninitialized additional_key (moneromooo-monero)
Diffstat (limited to 'src/device/device_ledger.cpp')
-rw-r--r-- | src/device/device_ledger.cpp | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/src/device/device_ledger.cpp b/src/device/device_ledger.cpp index eba633da8..2d91b881b 100644 --- a/src/device/device_ledger.cpp +++ b/src/device/device_ledger.cpp @@ -320,7 +320,9 @@ namespace hw { bool device_ledger::reset() { reset_buffer(); int offset = set_command_header_noopt(INS_RESET); - memmove(this->buffer_send+offset, MONERO_VERSION, strlen(MONERO_VERSION)); + const size_t verlen = strlen(MONERO_VERSION); + ASSERT_X(offset + verlen <= BUFFER_SEND_SIZE, "MONERO_VERSION is too long") + memmove(this->buffer_send+offset, MONERO_VERSION, verlen); offset += strlen(MONERO_VERSION); this->buffer_send[4] = offset-5; this->length_send = offset; |