The frame length and the offset (which depends on the device-supplied frame type) are derived from device bytes, so validate both the source read (against the response buffer) and the destination write (against the image buffer) before copying. A malicious or malfunctioning device could otherwise drive a negative (huge once unsigned) or out-of-bounds length. Note: the response is reassembled across several USB transfers, so the bound here is the response buffer capacity rather than a single transfer's actual_length. Reported by: Keith Linneman (LinnemanLabs)
History
LibFPrint was originally developed as part of an academic project at the University Of Manchester.
It aimed to hide the differences between consumer fingerprint scanners and provide a single uniform API to application developers.
Goal
The ultimate goal of the FPrint project is to make fingerprint scanners widely and easily usable under common Linux environments.
License
Section 6 of the license states that for compiled works that use
this library, such works must include LibFPrint copyright notices
alongside the copyright notices for the other parts of the work.
LibFPrint includes code from NIST's NBIS software distribution.
We include Bozorth3 from the US Export Controlled distribution, which we have determined to be fine being shipped in an open source project.
Get in touch
- IRC -
#fprint@irc.oftc.net - Matrix -
#fprint:matrix.orgbridged to the IRC channel - MailingList - low traffic, not much used these days