git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] url: do not allow %00 to represent NULL in URLs

From
René Scharfe <l.s.r@web.de>
Date
Jun 4, 2019, 05:01 UTC
Message-ID
<ca09cb2f-e376-1491-102d-0b06e49530a4@web.de>
In-Reply-To
<20190603204526.7723-3-matvore@google.com>
Am 03.06.19 um 22:45 schrieb Matthew DeVore:
Show 5 quoted lines
> There is no reason to allow %00 to terminate a string, so do not allow it.
> Otherwise, we end up returning arbitrary content in the string (that which is
> after the %00) which is effectively hidden from callers and can escape sanity
> checks and validation, and possible be used in tandem with a security
> vulnerability to introduce a payload.

It's a bit hard to see with the (extended, but still) limited context, but url_decode_internal() effectively returns a NUL-terminated string, even though it does use a strbuf parameter named "out" for temporary storage. So callers really have no use for decoded NULs, and this change thus makes sense to me.

Show 34 quoted lines
>
> Signed-off-by: Matthew DeVore <matvore@google.com>
> ---
>  url.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/url.c b/url.c
> index c0bb4e23c3..cf791cb139 100644
> --- a/url.c
> +++ b/url.c
> @@ -41,21 +41,21 @@ static char *url_decode_internal(const char **query, int len,
>  		if (!c)
>  			break;
>  		if (stop_at && strchr(stop_at, c)) {
>  			q++;
>  			len--;
>  			break;
>  		}
>
>  		if (c == '%' && len >= 3) {
>  			int val = hex2chr(q + 1);
> -			if (0 <= val) {
> +			if (0 < val) {
>  				strbuf_addch(out, val);
>  				q += 3;
>  				len -= 3;
>  				continue;
>  			}
>  		}
>
>  		if (decode_plus && c == '+')
>  			strbuf_addch(out, ' ');
>  		else
>
Previous: Matthew DeVoreNext: Matthew DeVore
Message 5 of 9 in “Harden url.c URL-decoding logic”
  1. 0/2 Harden url.c URL-decoding logicMatthew DeVore, Jun 3, 2019
  2. 2/2 url: do not allow %00 to represent NULL in URLsMatthew DeVore, Jun 3, 2019
  3. brian m. carlsonJun 4, 2019
  4. Matthew DeVoreJun 4, 2019
  5. René ScharfeJun 4, 2019
  6. Matthew DeVoreJun 4, 2019
  7. 1/2 url: do not read past end of bufferMatthew DeVore, Jun 3, 2019
  8. René ScharfeJun 4, 2019
  9. Matthew DeVoreJun 4, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.