Skip to content
Permalink
Browse files

Merge PR #3586: Murmur: fix Denial of Service vulnerability in msgCha…

…nnelState()
  • Loading branch information...
davidebeatrici committed Jan 25, 2019
2 parents e31d267 + 3edc46f commit 15f268cfd41647394618cdbe921f3bf13923cd59
Showing with 7 additions and 0 deletions.
  1. +7 −0 src/murmur/Messages.cpp
@@ -1062,6 +1062,13 @@ void Server::msgChannelState(ServerUser *uSource, MumbleProto::ChannelState &msg
}
}

if (msg.has_max_users()) {
if (! hasPermission(uSource, c, ChanACL::Write)) {
PERM_DENIED(uSource, c, ChanACL::Write);
return;
}
}

// All permission checks done -- the update is good.

if (p) {

0 comments on commit 15f268c

Please sign in to comment.
You can’t perform that action at this time.