mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-10-06 07:47:32 +00:00
improve emulator downloads with out of bounds checks
This commit is contained in:
@@ -3299,10 +3299,33 @@ static void PacketReceived(PacketCommandNG *packet) {
|
||||
if (packet->length < sizeof(download_req_t)) {
|
||||
break;
|
||||
}
|
||||
|
||||
if (mem == NULL) {
|
||||
reply_download_done(CMD_DOWNLOAD_EML_BIGBUF, 0, 0);
|
||||
LED_B_OFF();
|
||||
break;
|
||||
}
|
||||
|
||||
const download_req_t *dreq = (const download_req_t *)packet->data.asBytes;
|
||||
uint32_t startidx = dreq->start_index;
|
||||
uint32_t numofbytes = dreq->bytes;
|
||||
|
||||
// We report the emulator memory size in capabilities_t, so honour it
|
||||
// here as well. Without this a client asking for more than the
|
||||
// emulator holds reads on past it into the rest of BigBuf
|
||||
uint32_t em_size = BigBuf_get_EM_size();
|
||||
if (startidx >= em_size) {
|
||||
Dbprintf("Emulator memory download starts past the end, %u >= %u", startidx, em_size);
|
||||
reply_download_done(CMD_DOWNLOAD_EML_BIGBUF, 0, 0);
|
||||
LED_B_OFF();
|
||||
break;
|
||||
}
|
||||
|
||||
if (startidx + numofbytes > em_size) {
|
||||
Dbprintf("Emulator memory is %u bytes, truncating download of %u to %u", em_size, numofbytes, em_size - startidx);
|
||||
numofbytes = em_size - startidx;
|
||||
}
|
||||
|
||||
// arg0 = startindex
|
||||
// arg1 = length bytes to transfer
|
||||
// arg2 = RFU
|
||||
|
||||
@@ -2017,9 +2017,9 @@ static int CmdHFiClassESave(const char *Cmd) {
|
||||
CLIParamStrToBuf(arg_get_str(ctx, 1), (uint8_t *)filename, FILE_PATH_SIZE, &fnlen);
|
||||
uint16_t bytes = arg_get_int_def(ctx, 2, 256);
|
||||
|
||||
if (bytes > 4096) {
|
||||
PrintAndLogEx(WARNING, "Emulator memory is max 4096bytes. Truncating %u to 4096", bytes);
|
||||
bytes = 4096;
|
||||
if (bytes > g_conn.em_size) {
|
||||
PrintAndLogEx(WARNING, "Emulator memory is max %u bytes. Truncating %u to %u", g_conn.em_size, bytes, g_conn.em_size);
|
||||
bytes = g_conn.em_size;
|
||||
}
|
||||
|
||||
CLIParserFree(ctx);
|
||||
@@ -2077,9 +2077,9 @@ static int CmdHFiClassEView(const char *Cmd) {
|
||||
|
||||
CLIParserFree(ctx);
|
||||
|
||||
if (bytes > 4096) {
|
||||
PrintAndLogEx(WARNING, "Emulator memory is max 4096bytes. Truncating %u to 4096", bytes);
|
||||
bytes = 4096;
|
||||
if (bytes > g_conn.em_size) {
|
||||
PrintAndLogEx(WARNING, "Emulator memory is max %u bytes. Truncating %u to %u", g_conn.em_size, bytes, g_conn.em_size);
|
||||
bytes = g_conn.em_size;
|
||||
}
|
||||
|
||||
if (bytes % 8 != 0) {
|
||||
|
||||
Reference in New Issue
Block a user