NetworkRTCSocketCocoa extractDataMessages should not read too much data
Created attachment 419578 [details] Patch
Created attachment 419583 [details] Patch
Created attachment 419588 [details] Patch
Comment on attachment 419588 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=419588&action=review > Source/WebCore/Modules/mediastream/STUNMessageParsing.cpp:96 > + bool canReadLength = size >= 2; > + size_t length = canReadLength ? be16toh(*reinterpret_cast<const uint16_t*>(data)) : 0; > + if (!canReadLength || length > size - 2) { `2` would be better as a named const initialized with sizeof > Source/WebCore/Modules/mediastream/STUNMessageParsing.cpp:106 > + data += 2; > + size -= 2; Ditto
Created attachment 419596 [details] Patch for landing
(In reply to Eric Carlson from comment #4) > Comment on attachment 419588 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=419588&action=review > > > Source/WebCore/Modules/mediastream/STUNMessageParsing.cpp:96 > > + bool canReadLength = size >= 2; > > + size_t length = canReadLength ? be16toh(*reinterpret_cast<const uint16_t*>(data)) : 0; > > + if (!canReadLength || length > size - 2) { > > `2` would be better as a named const initialized with sizeof > > > Source/WebCore/Modules/mediastream/STUNMessageParsing.cpp:106 > > + data += 2; > > + size -= 2; > > Ditto Done, thanks!
<rdar://problem/73962727>
Comment on attachment 419596 [details] Patch for landing win failure is unrelated
Committed r272504: <https://commits.webkit.org/r272504> All reviewed patches have been landed. Closing bug and clearing flags on attachment 419596 [details].