]> The Tcpdump Group git mirrors - tcpdump/blobdiff - print-mpls.c
CVE-2016-7931/Add bounds and length checks.
[tcpdump] / print-mpls.c
index 039781ada2d1a751bd3f7ad0175356fe9d98d376..f6ee434e96d5a8cca81e6a92363a9e6333075e5a 100644 (file)
  * SUCH DAMAGE.
  */
 
-#define NETDISSECT_REWORKED
+/* \summary: Multi-Protocol Label Switching (MPLS) printer */
+
 #ifdef HAVE_CONFIG_H
 #include "config.h"
 #endif
 
-#include <tcpdump-stdinc.h>
+#include <netdissect-stdinc.h>
 
-#include "interface.h"
-#include "extract.h"                   /* must come after interface.h */
+#include "netdissect.h"
+#include "extract.h"
 #include "mpls.h"
 
 static const char *mpls_labelname[] = {
@@ -67,6 +68,10 @@ mpls_print(netdissect_options *ndo, const u_char *bp, u_int length)
        ND_PRINT((ndo, "MPLS"));
        do {
                ND_TCHECK2(*p, sizeof(label_entry));
+               if (length < sizeof(label_entry)) {
+                       ND_PRINT((ndo, "[|MPLS], length %u", length));
+                       return;
+               }
                label_entry = EXTRACT_32BITS(p);
                ND_PRINT((ndo, "%s(label %u",
                       (label_stack_depth && ndo->ndo_vflag) ? "\n\t" : " ",
@@ -81,6 +86,7 @@ mpls_print(netdissect_options *ndo, const u_char *bp, u_int length)
                ND_PRINT((ndo, ", ttl %u)", MPLS_TTL(label_entry)));
 
                p += sizeof(label_entry);
+               length -= sizeof(label_entry);
        } while (!MPLS_STACK(label_entry));
 
        /*
@@ -123,6 +129,11 @@ mpls_print(netdissect_options *ndo, const u_char *bp, u_int length)
                 * Cisco sends control-plane traffic MPLS-encapsulated in
                 * this fashion.
                 */
+               ND_TCHECK(*p);
+               if (length < 1) {
+                       /* nothing to print */
+                       return;
+               }
                switch(*p) {
 
                case 0x45:
@@ -186,11 +197,7 @@ mpls_print(netdissect_options *ndo, const u_char *bp, u_int length)
                break;
 
        case PT_IPV6:
-#ifdef INET6
                ip6_print(ndo, p, length - (p - bp));
-#else
-               ND_PRINT((ndo, "IPv6, length: %u", length));
-#endif
                break;
 
        case PT_OSI: