mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
fix(nimble): Fix vulnerabilities in NimBLE examples
This commit is contained in:
@@ -19,8 +19,8 @@
|
||||
static const char *tag = "NimBLE_CTS_CENT";
|
||||
static int ble_cts_cent_gap_event(struct ble_gap_event *event, void *arg);
|
||||
|
||||
static char *day_of_week[7] = {
|
||||
"Unknown"
|
||||
static char *day_of_week[8] = {
|
||||
"Unknown",
|
||||
"Monday",
|
||||
"Tuesday",
|
||||
"Wednesday",
|
||||
@@ -33,10 +33,14 @@ void ble_store_config_init(void);
|
||||
static void ble_cts_cent_scan(void);
|
||||
|
||||
void printtime(struct ble_svc_cts_curr_time ctime) {
|
||||
uint8_t dow = ctime.et_256.d_d_t.day_of_week;
|
||||
const char *dow_str = (dow >= 1 && dow <= 7) ? day_of_week[dow] : day_of_week[0];
|
||||
if (dow >= 8) {
|
||||
dow = 0;
|
||||
}
|
||||
ESP_LOGI(tag, "Date : %d/%d/%d %s", ctime.et_256.d_d_t.d_t.day,
|
||||
ctime.et_256.d_d_t.d_t.month,
|
||||
ctime.et_256.d_d_t.d_t.year,
|
||||
day_of_week[ctime.et_256.d_d_t.day_of_week]);
|
||||
ctime.et_256.d_d_t.d_t.year, dow_str);
|
||||
ESP_LOGI(tag, "hours : %d minutes : %d ",
|
||||
ctime.et_256.d_d_t.d_t.hours,
|
||||
ctime.et_256.d_d_t.d_t.minutes);
|
||||
@@ -55,6 +59,7 @@ ble_cts_cent_on_read(uint16_t conn_handle,
|
||||
struct ble_gatt_attr *attr,
|
||||
void *arg)
|
||||
{
|
||||
int rc = 0;
|
||||
struct ble_svc_cts_curr_time ctime; /* store the read time */
|
||||
MODLOG_DFLT(INFO, "Read Current time complete; status=%d conn_handle=%d\n",
|
||||
error->status, conn_handle);
|
||||
@@ -66,8 +71,12 @@ ble_cts_cent_on_read(uint16_t conn_handle,
|
||||
goto err;
|
||||
}
|
||||
MODLOG_DFLT(INFO, "\n");
|
||||
ble_hs_mbuf_to_flat(attr->om, &ctime, sizeof(ctime), NULL);
|
||||
printtime(ctime);
|
||||
rc = ble_hs_mbuf_to_flat(attr->om, &ctime, sizeof(ctime), NULL);
|
||||
if (rc == 0 && ctime.et_256.d_d_t.day_of_week <= 7) {
|
||||
printtime(ctime);
|
||||
} else {
|
||||
MODLOG_DFLT(WARN, "Invalid CTS time data; rc=%d day_of_week=%d\n", rc, ctime.et_256.d_d_t.day_of_week);
|
||||
}
|
||||
return 0;
|
||||
err:
|
||||
/* Terminate the connection. */
|
||||
@@ -234,7 +243,7 @@ ext_ble_cts_cent_should_connect(const struct ble_gap_ext_disc_desc *disc)
|
||||
/* Search if cts UUID is advertised */
|
||||
if (disc->data[offset + 1] == 0x03) {
|
||||
int temp = 2;
|
||||
while(temp < disc->data[offset + 1]) {
|
||||
while (temp < ad_struct_len) {
|
||||
if(disc->data[offset + temp] == 0x05 &&
|
||||
disc->data[offset + temp + 1] == 0x18) {
|
||||
return 1;
|
||||
@@ -491,7 +500,7 @@ ble_cts_cent_gap_event(struct ble_gap_event *event, void *arg)
|
||||
#else
|
||||
#if MYNEWT_VAL(BLE_GATTC)
|
||||
/*** Go for service discovery after encryption has been successfully enabled ***/
|
||||
rc = peer_disc_all(event->connect.conn_handle,
|
||||
rc = peer_disc_all(event->enc_change.conn_handle,
|
||||
ble_cts_cent_on_disc_complete, NULL);
|
||||
if (rc != 0) {
|
||||
MODLOG_DFLT(ERROR, "Failed to discover services; rc=%d\n", rc);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2017-2023 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2017-2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -16,6 +16,7 @@
|
||||
#include <time.h>
|
||||
#include "sys/time.h"
|
||||
|
||||
static const char *TAG = "CTS_GATT_SVR";
|
||||
|
||||
void
|
||||
gatt_svr_register_cb(struct ble_gatt_register_ctxt *ctxt, void *arg)
|
||||
@@ -85,7 +86,21 @@ int fetch_current_time(struct ble_svc_cts_curr_time *ctime) {
|
||||
int set_current_time(struct ble_svc_cts_curr_time ctime) {
|
||||
time_t now;
|
||||
struct tm timeinfo;
|
||||
struct timeval tv_now;
|
||||
struct timeval tv_now = {0};
|
||||
|
||||
/* Basic sanity validation for incoming time fields */
|
||||
if (ctime.et_256.d_d_t.d_t.year < 1900 ||
|
||||
ctime.et_256.d_d_t.d_t.year > 9999 ||
|
||||
ctime.et_256.d_d_t.d_t.month < 1 || ctime.et_256.d_d_t.d_t.month > 12 ||
|
||||
ctime.et_256.d_d_t.d_t.day < 1 || ctime.et_256.d_d_t.d_t.day > 31 ||
|
||||
ctime.et_256.d_d_t.d_t.hours > 23 ||
|
||||
ctime.et_256.d_d_t.d_t.minutes > 59 ||
|
||||
ctime.et_256.d_d_t.d_t.seconds > 59 ||
|
||||
ctime.et_256.d_d_t.day_of_week < 1 || ctime.et_256.d_d_t.day_of_week > 7) {
|
||||
ESP_LOGE(TAG, "Invalid current time parameters");
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* fill date_time */
|
||||
timeinfo.tm_year= ctime.et_256.d_d_t.d_t.year - 1900 ;
|
||||
timeinfo.tm_mon = ctime.et_256.d_d_t.d_t.month - 1;
|
||||
@@ -95,7 +110,12 @@ int set_current_time(struct ble_svc_cts_curr_time ctime) {
|
||||
timeinfo.tm_sec = ctime.et_256.d_d_t.d_t.seconds;
|
||||
timeinfo.tm_wday = ctime.et_256.d_d_t.day_of_week - 1;
|
||||
now = mktime(&timeinfo);
|
||||
if (now == (time_t)-1) {
|
||||
ESP_LOGE(TAG, "Failed to convert current time");
|
||||
return -1;
|
||||
}
|
||||
tv_now.tv_sec = now;
|
||||
tv_now.tv_usec = 0;
|
||||
settimeofday(&tv_now, NULL);
|
||||
/* set the last updated */
|
||||
gettimeofday(&last_updated, NULL);
|
||||
|
||||
Reference in New Issue
Block a user