mirror of
https://github.com/cesanta/mongoose.git
synced 2026-10-02 06:22:52 +07:00
Merge commit from fork
avoid OOB reads in path_is_sane
This commit is contained in:
+9
-6
@@ -25256,13 +25256,16 @@ int mg_check_ip_acl(struct mg_str acl, struct mg_addr *remote_ip) {
|
||||
bool mg_path_is_sane(const struct mg_str path) {
|
||||
const char *s = path.buf;
|
||||
size_t n = path.len;
|
||||
if (path.buf[0] == '~') return false; // Starts with ~
|
||||
if (path.buf[0] == '.' && path.buf[1] == '.') return false; // Starts with ..
|
||||
for (; s[0] != '\0' && n > 0; s++, n--) {
|
||||
if ((s[0] == '/' || s[0] == '\\') && n >= 2) { // Subdir?
|
||||
if (s[1] == '.' && s[2] == '.') return false; // Starts with ..
|
||||
}
|
||||
if (n == 0 || path.buf[0] == '\0') return true;
|
||||
if (s[0] == '~') return false; // Starts with ~
|
||||
if (s[0] == '.' && n > 1 && s[1] == '.')
|
||||
return false; // Starts with ..
|
||||
for (; n > 0 && s[0] != '\0'; s++, n--) {
|
||||
if ((s[0] == '/' || s[0] == '\\') && n >= 2 && s[1] == '.' && n > 2 &&
|
||||
s[2] == '.')
|
||||
return false; // Subdir starts with ..
|
||||
}
|
||||
if (n > 0) return false; // embedded nul (terminator not counted in len)
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
+9
-6
@@ -143,13 +143,16 @@ int mg_check_ip_acl(struct mg_str acl, struct mg_addr *remote_ip) {
|
||||
bool mg_path_is_sane(const struct mg_str path) {
|
||||
const char *s = path.buf;
|
||||
size_t n = path.len;
|
||||
if (path.buf[0] == '~') return false; // Starts with ~
|
||||
if (path.buf[0] == '.' && path.buf[1] == '.') return false; // Starts with ..
|
||||
for (; s[0] != '\0' && n > 0; s++, n--) {
|
||||
if ((s[0] == '/' || s[0] == '\\') && n >= 2) { // Subdir?
|
||||
if (s[1] == '.' && s[2] == '.') return false; // Starts with ..
|
||||
}
|
||||
if (n == 0 || path.buf[0] == '\0') return true;
|
||||
if (s[0] == '~') return false; // Starts with ~
|
||||
if (s[0] == '.' && n > 1 && s[1] == '.')
|
||||
return false; // Starts with ..
|
||||
for (; n > 0 && s[0] != '\0'; s++, n--) {
|
||||
if ((s[0] == '/' || s[0] == '\\') && n >= 2 && s[1] == '.' && n > 2 &&
|
||||
s[2] == '.')
|
||||
return false; // Subdir starts with ..
|
||||
}
|
||||
if (n > 0) return false; // embedded nul (terminator not counted in len)
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
+13
-1
@@ -2554,7 +2554,18 @@ static void test_str(void) {
|
||||
ASSERT(strcmp(buf, "[164:2100:0:0:0:0:0:0]:3 7") == 0);
|
||||
}
|
||||
|
||||
ASSERT(mg_path_is_sane(mg_str(".")) == true);
|
||||
{
|
||||
char s[1] = ".";
|
||||
ASSERT(mg_path_is_sane(mg_str_n(s, 1)) == true);
|
||||
}
|
||||
{
|
||||
char s[2] = "/.";
|
||||
ASSERT(mg_path_is_sane(mg_str_n(s, 2)) == true);
|
||||
}
|
||||
{
|
||||
char s[3] = "a/.";
|
||||
ASSERT(mg_path_is_sane(mg_str_n(s, 3)) == true);
|
||||
}
|
||||
ASSERT(mg_path_is_sane(mg_str("")) == true);
|
||||
ASSERT(mg_path_is_sane(mg_str("a.b")) == true);
|
||||
ASSERT(mg_path_is_sane(mg_str("a..b")) == true);
|
||||
@@ -2570,6 +2581,7 @@ static void test_str(void) {
|
||||
ASSERT(mg_path_is_sane(mg_str("a/../b")) == false);
|
||||
ASSERT(mg_path_is_sane(mg_str_n("a/..", 2)) == true);
|
||||
ASSERT(mg_path_is_sane(mg_str_n("a/../b", 2)) == true);
|
||||
ASSERT(mg_path_is_sane(mg_str_n("a\0/../b", 7)) == false);
|
||||
}
|
||||
|
||||
static void fn1(struct mg_connection *c, int ev, void *ev_data) {
|
||||
|
||||
Reference in New Issue
Block a user