Page MenuHomeFreeBSD

libfetch: Limit response line length
ClosedPublic

Authored by des on Fri, Sep 25, 10:37 AM.
Tags
None
Referenced Files
F175069342: D60007.id.diff
Thu, Oct 8, 1:00 AM
F175019204: D60007.id187987.diff
Wed, Oct 7, 4:34 PM
Unknown Object (File)
Wed, Oct 7, 1:22 PM
Unknown Object (File)
Wed, Oct 7, 12:44 PM
Unknown Object (File)
Wed, Oct 7, 12:10 PM
Unknown Object (File)
Wed, Oct 7, 10:47 AM
Unknown Object (File)
Wed, Oct 7, 6:23 AM
Unknown Object (File)
Wed, Oct 7, 6:23 AM
Subscribers

Details

Summary

When reading an FTP or HTTP response, error out if we read 64 kB before
hitting a newline. Otherwise a runaway or malicious server could have
us spinning for quite a while allocating more and more memory before we
gave up or crashed.

MFC after: 1 week

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77440
Build 74323: arc lint + arc unit

Event Timeline

des requested review of this revision.Fri, Sep 25, 10:37 AM
lib/libfetch/common.c
1474

I don't really follow: curr->pos is the absolute offset into the buffer. Shouldn't we be starting from 0 for each line?

lib/libfetch/common.c
1474

conn->pos is initially the end of the previous line, so the check here (copy-pasted from below) is incorrect.

The commit log message should explain why.

This revision is now accepted and ready to land.Wed, Sep 30, 2:29 PM
This revision was automatically updated to reflect the committed changes.