--- heartbeat-1.2.4/lib/clplumbing/cl_netstring.c 2004-08-05 12:30:47.000000000 -0600 +++ heartbeat-1.2.5/lib/clplumbing/cl_netstring.c 2006-08-13 22:27:22.000000000 -0600 @@ -257,6 +257,9 @@ peel_netstring(const char * s, const cha *data = sp; sp += (*len); + if (sp >= smax) { + return(HA_FAIL); + } if (*sp != ','){ return(HA_FAIL); }