Skip to content

**Description** #26491

@Duck1992

Description

@Duck1992

Description
This PR added a bounds check before memcpy operation in name_parse() function to prevent potential out-of-bounds reads. This potential vulnerability was cloned from libevent and was fixed in libevent/libevent@96f64a0.

Reference:
libevent/libevent@96f64a0
CVE-2016-10195

最初由 @npt-1707TelegramMessenger/Telegram-iOS#1740 发布

┆Issue is synchronized with this Jira Task

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions