Page MenuHomeFreeBSD

libfetch: Limit response line length
ClosedPublic

Authored by des on Fri, Sep 25, 10:37 AM.
Tags
None
Referenced Files
F174769441: D60007.diff
Mon, Oct 5, 9:23 PM
F174761112: D60007.id188225.diff
Mon, Oct 5, 7:56 PM
F174687464: D60007.id188225.diff
Mon, Oct 5, 5:05 AM
F174674206: D60007.id188225.diff
Mon, Oct 5, 3:02 AM
F174671811: D60007.diff
Mon, Oct 5, 2:37 AM
F174666085: D60007.id.diff
Mon, Oct 5, 1:39 AM
Unknown Object (File)
Sun, Oct 4, 3:16 PM
Unknown Object (File)
Sun, Oct 4, 10:11 AM
Subscribers

Details

Summary

When reading an FTP or HTTP response, error out if we read 64 kB before
hitting a newline. Otherwise a runaway or malicious server could have
us spinning for quite a while allocating more and more memory before we
gave up or crashed.

MFC after: 1 week

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77301
Build 74184: arc lint + arc unit

Event Timeline

des requested review of this revision.Fri, Sep 25, 10:37 AM
lib/libfetch/common.c
1474

I don't really follow: curr->pos is the absolute offset into the buffer. Shouldn't we be starting from 0 for each line?

lib/libfetch/common.c
1474

conn->pos is initially the end of the previous line, so the check here (copy-pasted from below) is incorrect.

The commit log message should explain why.

This revision is now accepted and ready to land.Wed, Sep 30, 2:29 PM
This revision was automatically updated to reflect the committed changes.