aboutsummaryrefslogtreecommitdiffstats
path: root/src/eap_peer/eap_fast_pac.c
diff options
context:
space:
mode:
authorJouni Malinen <j@w1.fi>2010-01-10 20:04:59 (GMT)
committerJouni Malinen <j@w1.fi>2010-01-10 20:04:59 (GMT)
commit4edc5210684e40f785d37d42f3865de3eb5d6df6 (patch)
treea9558cf602895884d89387906739ee3306c8441f /src/eap_peer/eap_fast_pac.c
parenta416fb47eb61f879b8275691dbbc56b2430faa1a (diff)
downloadhostap-4edc5210684e40f785d37d42f3865de3eb5d6df6.zip
hostap-4edc5210684e40f785d37d42f3865de3eb5d6df6.tar.gz
hostap-4edc5210684e40f785d37d42f3865de3eb5d6df6.tar.bz2
EAP-FAST peer: Clean up PAC writing function
Use more explicit validation of input parameters and clean up the writes by using a local end-of-buffer variable to simplify calculations.
Diffstat (limited to 'src/eap_peer/eap_fast_pac.c')
-rw-r--r--src/eap_peer/eap_fast_pac.c29
1 files changed, 15 insertions, 14 deletions
diff --git a/src/eap_peer/eap_fast_pac.c b/src/eap_peer/eap_fast_pac.c
index 77893d6..541cce5 100644
--- a/src/eap_peer/eap_fast_pac.c
+++ b/src/eap_peer/eap_fast_pac.c
@@ -480,8 +480,10 @@ static void eap_fast_write(char **buf, char **pos, size_t *buf_len,
{
size_t i, need;
int ret;
+ char *end;
- if (data == NULL || *buf == NULL)
+ if (data == NULL || buf == NULL || *buf == NULL ||
+ pos == NULL || *pos == NULL || *pos < *buf)
return;
need = os_strlen(field) + len * 2 + 30;
@@ -498,32 +500,31 @@ static void eap_fast_write(char **buf, char **pos, size_t *buf_len,
*buf = nbuf;
*buf_len += need;
}
+ end = *buf + *buf_len;
- ret = os_snprintf(*pos, *buf + *buf_len - *pos, "%s=", field);
- if (ret < 0 || ret >= *buf + *buf_len - *pos)
+ ret = os_snprintf(*pos, end - *pos, "%s=", field);
+ if (ret < 0 || ret >= end - *pos)
return;
*pos += ret;
- *pos += wpa_snprintf_hex(*pos, *buf + *buf_len - *pos, data, len);
- ret = os_snprintf(*pos, *buf + *buf_len - *pos, "\n");
- if (ret < 0 || ret >= *buf + *buf_len - *pos)
+ *pos += wpa_snprintf_hex(*pos, end - *pos, data, len);
+ ret = os_snprintf(*pos, end - *pos, "\n");
+ if (ret < 0 || ret >= end - *pos)
return;
*pos += ret;
if (txt) {
- ret = os_snprintf(*pos, *buf + *buf_len - *pos,
- "%s-txt=", field);
- if (ret < 0 || ret >= *buf + *buf_len - *pos)
+ ret = os_snprintf(*pos, end - *pos, "%s-txt=", field);
+ if (ret < 0 || ret >= end - *pos)
return;
*pos += ret;
for (i = 0; i < len; i++) {
- ret = os_snprintf(*pos, *buf + *buf_len - *pos,
- "%c", data[i]);
- if (ret < 0 || ret >= *buf + *buf_len - *pos)
+ ret = os_snprintf(*pos, end - *pos, "%c", data[i]);
+ if (ret < 0 || ret >= end - *pos)
return;
*pos += ret;
}
- ret = os_snprintf(*pos, *buf + *buf_len - *pos, "\n");
- if (ret < 0 || ret >= *buf + *buf_len - *pos)
+ ret = os_snprintf(*pos, end - *pos, "\n");
+ if (ret < 0 || ret >= end - *pos)
return;
*pos += ret;
}