From 24750d4b748fefa03d09fcfd6d45056faca354e0 Mon Sep 17 00:00:00 2001 From: Keane O'Kelley Date: Fri, 6 Oct 2023 20:53:17 -0400 Subject: [PATCH] Fix buffer overflow in performRtspHandshake (CVE-2023-42800) --- src/RtspConnection.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/RtspConnection.c b/src/RtspConnection.c index 18e15dd..a75572b 100644 --- a/src/RtspConnection.c +++ b/src/RtspConnection.c @@ -776,7 +776,8 @@ int performRtspHandshake(PSERVER_INFORMATION serverInfo) { (StreamConfig.streamingRemotely != STREAM_CFG_REMOTE || CHANNEL_COUNT_FROM_AUDIO_CONFIGURATION(StreamConfig.audioConfiguration) <= 2)) { // If we have an RTSP URL string and it was successfully parsed, use that string if (serverInfo->rtspSessionUrl != NULL && parseUrlAddrFromRtspUrlString(serverInfo->rtspSessionUrl, urlAddr, sizeof(urlAddr))) { - strcpy(rtspTargetUrl, serverInfo->rtspSessionUrl); + PltSafeStrcpy(rtspTargetUrl, sizeof(rtspTargetUrl), serverInfo->rtspSessionUrl); + rtspTargetUrl[sizeof(rtspTargetUrl) - 1] = '\0'; } else { // If an RTSP URL string was not provided or failed to parse, we will construct one now as best we can.