chaojianhu
a0d1cbdacf
hw/net: Fix a heap overflow in xlnx.xps-ethernetlite
...
The .receive callback of xlnx.xps-ethernetlite doesn't check the length
of data before calling memcpy. As a result, the NetClientState object in
heap will be overflowed. All versions of qemu with xlnx.xps-ethernetlite
will be affected.
Reported-by: chaojianhu <chaojianhu@hotmail.com>
Signed-off-by: chaojianhu <chaojianhu@hotmail.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
2016-08-09 15:27:18 +08:00
..
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-12 16:19:16 +02:00
2016-07-19 20:18:02 +02:00
2016-07-18 16:16:20 +08:00
2016-06-02 10:42:29 +08:00
2016-07-19 20:18:02 +02:00
2016-06-27 16:39:56 +01:00
2016-06-02 10:42:29 +08:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-18 16:17:02 +08:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-12 16:20:46 +02:00
2016-06-02 10:42:28 +08:00
2016-06-02 10:42:28 +08:00
2016-08-09 11:45:30 +08:00
2016-06-16 18:39:03 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-01-29 15:07:23 +00:00
2016-07-12 16:20:46 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-06-20 17:22:15 +01:00
2016-07-29 00:33:49 +03:00
2016-07-21 20:12:37 +01:00
2016-06-28 10:13:57 +08:00
2016-08-09 15:24:56 +08:00
2016-07-12 16:20:46 +02:00
2016-07-12 16:20:46 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-07-19 20:18:02 +02:00
2016-08-09 15:27:18 +08:00