mirror of
https://github.com/ZLMediaKit/ZLMediaKit.git
synced 2026-07-28 21:14:03 +08:00
fix: limit AMF decoder nesting depth
This commit is contained in:
@@ -452,6 +452,17 @@ const std::string& AMFEncoder::data() const {
|
||||
|
||||
//////////////////Decoder//////////////////
|
||||
|
||||
AMFDecoder::DepthGuard::DepthGuard(AMFDecoder &decoder) : _decoder(decoder) {
|
||||
if (_decoder.depth >= AMFDecoder::kMaxDepth) {
|
||||
throw std::runtime_error("Maximum AMF nesting depth exceeded");
|
||||
}
|
||||
++_decoder.depth;
|
||||
}
|
||||
|
||||
AMFDecoder::DepthGuard::~DepthGuard() {
|
||||
--_decoder.depth;
|
||||
}
|
||||
|
||||
uint8_t AMFDecoder::front() {
|
||||
if (pos >= buf.size()) {
|
||||
throw std::runtime_error("Not enough data");
|
||||
@@ -625,6 +636,7 @@ std::string AMFDecoder::load_key() {
|
||||
}
|
||||
|
||||
AMFValue AMFDecoder::load_object() {
|
||||
DepthGuard depth_guard(*this);
|
||||
AMFValue object(AMF_OBJECT);
|
||||
if (pop_front() != AMF0_OBJECT) {
|
||||
throw std::runtime_error("Expected an object");
|
||||
@@ -643,6 +655,7 @@ AMFValue AMFDecoder::load_object() {
|
||||
}
|
||||
|
||||
AMFValue AMFDecoder::load_ecma() {
|
||||
DepthGuard depth_guard(*this);
|
||||
/* ECMA array is the same as object, with 4 extra zero bytes */
|
||||
AMFValue object(AMF_ECMA_ARRAY);
|
||||
if (pop_front() != AMF0_ECMA_ARRAY) {
|
||||
@@ -665,6 +678,7 @@ AMFValue AMFDecoder::load_ecma() {
|
||||
return object;
|
||||
}
|
||||
AMFValue AMFDecoder::load_arr() {
|
||||
DepthGuard depth_guard(*this);
|
||||
/* ECMA array is the same as object, with 4 extra zero bytes */
|
||||
AMFValue object(AMF_STRICT_ARRAY);
|
||||
if (pop_front() != AMF0_STRICT_ARRAY) {
|
||||
@@ -689,4 +703,3 @@ AMFValue AMFDecoder::load_arr() {
|
||||
AMFDecoder::AMFDecoder(const BufferLikeString &buf_in, size_t pos_in, int version_in) :
|
||||
buf(buf_in), pos(pos_in), version(version_in) {
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user