From 567e344ad78af3118631aebca7a237635541a2c1 Mon Sep 17 00:00:00 2001 From: dmiller Date: Tue, 8 Jul 2014 15:17:12 +0000 Subject: [PATCH] Fix assertion failure in do_one_select_round Since the refactor in r33185, getting a good response for a host during a ping scan can remove all outstanding probes for that host, since we already know the host is up. This broke the existing iteration in some cases. I could force the crash with: nmap -sn -PS80-89 scanme.nmap.org Now we check explicitly for an empty list each time through the loop. --- scan_engine.cc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scan_engine.cc b/scan_engine.cc index f8cf9bad6..1ef80a7f0 100644 --- a/scan_engine.cc +++ b/scan_engine.cc @@ -4203,7 +4203,7 @@ static bool do_one_select_round(UltraScanInfo *USI, struct timeval *stime) { std::list::iterator nextProbeI; for (std::list::iterator probeI = host->probes_outstanding.begin(), end = host->probes_outstanding.end(); - probeI != end && numGoodSD < selectres; probeI = nextProbeI) { + probeI != end && numGoodSD < selectres && host->num_probes_outstanding() > 0; probeI = nextProbeI) { /* handleConnectResult may remove the probe at probeI, which invalidates * the iterator. We copy and increment it here instead of in the for-loop * statement to avoid incrementing an invalid iterator */