Re: [PATCH 2/3] imap-send: don't expect an ASN1_STRING to be NUL-terminated
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Sep 8, 2026, 01:17 UTC
- Message-ID
- <xmqqwlswzgmq.fsf@gitster.g>
- In-Reply-To
- <20260907211210.2621693-3-dev+git@drbeat.li>
Beat Bolli <dev+git@drbeat.li> writes:
Show 23 quoted lines
> - const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str);
> + int ret = 0;
> + size_t len = ASN1_STRING_get_length(asn1_str);
> + char *pattern = xmemdupz(ASN1_STRING_get0_data(asn1_str), len);
>
> /* embedded NUL characters may open a security hole */
> - if (memchr(pattern, '\0', ASN1_STRING_get_length(asn1_str)))
> - return 0;
> + if (memchr(pattern, '\0', len))
> + goto out;
>
> if (pattern[0] == '*' && pattern[1] == '.') {
> pattern += 2;
> if (!(host = strchr(host, '.')))
> - return 0;
> + goto out;
> host++;
> }
>
> - return *host && *pattern && !strcasecmp(host, pattern);
> + ret = *host && *pattern && !strcasecmp(host, pattern);
> +out:
> + free(pattern);There is a code path that increments the "pattern" variable by 2. Running free() on it would not have a pleasant outcome.
The pattern we often employ in our codebase is to have a separate variable "char *pattern_to_free" and have it used only for a call to free().
> + return ret; > } > > static int verify_hostname(X509 *cert, const char *hostname)