git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 1/5] avoid parse_sha1_header() accessing memory out of bound

From
LYLiu Yubao <yubao.liu@gmail.com>
Date
Dec 2, 2008, 01:51 UTC
Message-ID
<4934949B.70307@gmail.com>
In-Reply-To
<7voczws3np.fsf@gitster.siamese.dyndns.org>
Signed-off-by: Liu Yubao <yubao.liu@gmail.com>
---
 sha1_file.c |   15 +++++++++------
 1 files changed, 9 insertions(+), 6 deletions(-)
diff --git a/sha1_file.c b/sha1_file.c
index 6c0e251..efe6967 100644
--- a/sha1_file.c
+++ b/sha1_file.c
@@ -1245,8 +1245,9 @@ static void *unpack_sha1_rest(z_stream *stream, void *buffer, unsigned long size
  * too permissive for what we want to check. So do an anal
  * object header parse by hand.
  */
-static int parse_sha1_header(const char *hdr, unsigned long *sizep)
+static int parse_sha1_header(const char *hdr, unsigned long length, unsigned long *sizep)
 {
+	const char *hdr_end = hdr + length;
 	char type[10];
 	int i;
 	unsigned long size;
@@ -1254,10 +1255,10 @@ static int parse_sha1_header(const char *hdr, unsigned long *sizep)
 	/*
 	 * The type can be at most ten bytes (including the
 	 * terminating '\0' that we add), and is followed by
-	 * a space.
+	 * a space, at least one byte for size, and a '\0'.
 	 */
 	i = 0;
-	for (;;) {
+	while (hdr < hdr_end - 2) {
 		char c = *hdr++;
 		if (c == ' ')
 			break;
@@ -1265,6 +1266,8 @@ static int parse_sha1_header(const char *hdr, unsigned long *sizep)
 		if (i >= sizeof(type))
 			return -1;
 	}
+	if (' ' != *(hdr - 1))
+		return -1;
 	type[i] = 0;
 
 	/*
@@ -1275,7 +1278,7 @@ static int parse_sha1_header(const char *hdr, unsigned long *sizep)
 	if (size > 9)
 		return -1;
 	if (size) {
-		for (;;) {
+		while (hdr < hdr_end - 1) {
 			unsigned long c = *hdr - '0';
 			if (c > 9)
 				break;
@@ -1298,7 +1301,7 @@ static void *unpack_sha1_file(void *map, unsigned long mapsize, enum object_type
 	char hdr[8192];
 
 	ret = unpack_sha1_header(&stream, map, mapsize, hdr, sizeof(hdr));
-	if (ret < Z_OK || (*type = parse_sha1_header(hdr, size)) < 0)
+	if (ret < Z_OK || (*type = parse_sha1_header(hdr, stream.total_out, size)) < 0)
 		return NULL;
 
 	return unpack_sha1_rest(&stream, hdr, *size, sha1);
@@ -1982,7 +1985,7 @@ static int sha1_loose_object_info(const unsigned char *sha1, unsigned long *size
 	if (unpack_sha1_header(&stream, map, mapsize, hdr, sizeof(hdr)) < 0)
 		status = error("unable to unpack %s header",
 			       sha1_to_hex(sha1));
-	else if ((status = parse_sha1_header(hdr, &size)) < 0)
+	else if ((status = parse_sha1_header(hdr, stream.total_out, &size)) < 0)
 		status = error("unable to parse %s header", sha1_to_hex(sha1));
 	else if (sizep)
 		*sizep = size;
-- 
1.6.1.rc1.5.gde86c
Previous: Liu YubaoNext: Shawn O. Pearce
Message 9 of 27 in “two questions about the format of loose object”
  1. Liu YubaoDec 1, 2008
  2. Junio C HamanoDec 1, 2008
  3. Liu YubaoDec 1, 2008
  4. Jakub NarebskiDec 1, 2008
  5. Liu YubaoDec 2, 2008
  6. Shawn O. PearceDec 1, 2008
  7. Liu YubaoDec 2, 2008
  8. 0/5 support reading and writing uncompressed loose objectLiu Yubao, Dec 2, 2008
  9. 1/5 avoid parse_sha1_header() accessing memory out of boundLiu Yubao, Dec 2, 2008
  10. Shawn O. PearceDec 2, 2008
  11. Liu YubaoDec 3, 2008
  12. 2/5 don't die immediately when convert an invalid type nameLiu Yubao, Dec 2, 2008
  13. 3/5 optimize parse_sha1_header() a little by detecting object typeLiu Yubao, Dec 2, 2008
  14. Shawn O. PearceDec 2, 2008
  15. Liu YubaoDec 3, 2008
  16. 4/5 support reading uncompressed loose objectLiu Yubao, Dec 2, 2008
  17. Shawn O. PearceDec 2, 2008
  18. Liu YubaoDec 3, 2008
  19. 5/5 support writing uncompressed loose objectLiu Yubao, Dec 2, 2008
  20. Shawn O. PearceDec 2, 2008
  21. Liu YubaoDec 3, 2008
  22. Liu YubaoDec 2, 2008
  23. Nick AndrewDec 1, 2008
  24. Liu YubaoDec 2, 2008
  25. Shawn O. PearceDec 1, 2008
  26. Liu YubaoDec 2, 2008
  27. Nicolas PitreDec 4, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.