You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

165 lines
4.4 KiB

  1. From 1493b4466fa394b321d196ad63dd6a4fa395d337 Mon Sep 17 00:00:00 2001
  2. From: Andreas Schneider <asn@cryptomilk.org>
  3. Date: Wed, 3 Jun 2020 10:04:09 +0200
  4. Subject: [PATCH 1/4] sftpserver: Add missing NULL check for ssh_buffer_new()
  5. Thanks to Ramin Farajpour Cami for spotting this.
  6. Fixes T232
  7. Signed-off-by: Andreas Schneider <asn@cryptomilk.org>
  8. ---
  9. src/sftpserver.c | 6 ++++++
  10. 1 file changed, 6 insertions(+)
  11. diff --git a/src/sftpserver.c b/src/sftpserver.c
  12. index 5a2110e5..b639a2ce 100644
  13. --- a/src/sftpserver.c
  14. +++ b/src/sftpserver.c
  15. @@ -67,6 +67,12 @@ sftp_client_message sftp_get_client_message(sftp_session sftp) {
  16. /* take a copy of the whole packet */
  17. msg->complete_message = ssh_buffer_new();
  18. + if (msg->complete_message == NULL) {
  19. + ssh_set_error_oom(session);
  20. + sftp_client_message_free(msg);
  21. + return NULL;
  22. + }
  23. +
  24. ssh_buffer_add_data(msg->complete_message,
  25. ssh_buffer_get(payload),
  26. ssh_buffer_get_len(payload));
  27. --
  28. GitLab
  29. From dbfb7f44aa905a7103bdde9a198c1e9b0f480c2e Mon Sep 17 00:00:00 2001
  30. From: Andreas Schneider <asn@cryptomilk.org>
  31. Date: Wed, 3 Jun 2020 10:05:51 +0200
  32. Subject: [PATCH 2/4] sftpserver: Add missing return check for
  33. ssh_buffer_add_data()
  34. Signed-off-by: Andreas Schneider <asn@cryptomilk.org>
  35. ---
  36. src/sftpserver.c | 11 ++++++++---
  37. 1 file changed, 8 insertions(+), 3 deletions(-)
  38. diff --git a/src/sftpserver.c b/src/sftpserver.c
  39. index b639a2ce..9117f155 100644
  40. --- a/src/sftpserver.c
  41. +++ b/src/sftpserver.c
  42. @@ -73,9 +73,14 @@ sftp_client_message sftp_get_client_message(sftp_session sftp) {
  43. return NULL;
  44. }
  45. - ssh_buffer_add_data(msg->complete_message,
  46. - ssh_buffer_get(payload),
  47. - ssh_buffer_get_len(payload));
  48. + rc = ssh_buffer_add_data(msg->complete_message,
  49. + ssh_buffer_get(payload),
  50. + ssh_buffer_get_len(payload));
  51. + if (rc < 0) {
  52. + ssh_set_error_oom(session);
  53. + sftp_client_message_free(msg);
  54. + return NULL;
  55. + }
  56. ssh_buffer_get_u32(payload, &msg->id);
  57. --
  58. GitLab
  59. From 65ae496222018221080dd753a52f6d70bf3ca5f3 Mon Sep 17 00:00:00 2001
  60. From: Andreas Schneider <asn@cryptomilk.org>
  61. Date: Wed, 3 Jun 2020 10:10:11 +0200
  62. Subject: [PATCH 3/4] buffer: Reformat ssh_buffer_add_data()
  63. Signed-off-by: Andreas Schneider <asn@cryptomilk.org>
  64. ---
  65. src/buffer.c | 35 ++++++++++++++++++-----------------
  66. 1 file changed, 18 insertions(+), 17 deletions(-)
  67. diff --git a/src/buffer.c b/src/buffer.c
  68. index a2e6246a..476bc135 100644
  69. --- a/src/buffer.c
  70. +++ b/src/buffer.c
  71. @@ -299,28 +299,29 @@ int ssh_buffer_reinit(struct ssh_buffer_struct *buffer)
  72. */
  73. int ssh_buffer_add_data(struct ssh_buffer_struct *buffer, const void *data, uint32_t len)
  74. {
  75. - buffer_verify(buffer);
  76. + buffer_verify(buffer);
  77. - if (data == NULL) {
  78. - return -1;
  79. - }
  80. + if (data == NULL) {
  81. + return -1;
  82. + }
  83. - if (buffer->used + len < len) {
  84. - return -1;
  85. - }
  86. + if (buffer->used + len < len) {
  87. + return -1;
  88. + }
  89. - if (buffer->allocated < (buffer->used + len)) {
  90. - if(buffer->pos > 0)
  91. - buffer_shift(buffer);
  92. - if (realloc_buffer(buffer, buffer->used + len) < 0) {
  93. - return -1;
  94. + if (buffer->allocated < (buffer->used + len)) {
  95. + if (buffer->pos > 0) {
  96. + buffer_shift(buffer);
  97. + }
  98. + if (realloc_buffer(buffer, buffer->used + len) < 0) {
  99. + return -1;
  100. + }
  101. }
  102. - }
  103. - memcpy(buffer->data+buffer->used, data, len);
  104. - buffer->used+=len;
  105. - buffer_verify(buffer);
  106. - return 0;
  107. + memcpy(buffer->data + buffer->used, data, len);
  108. + buffer->used += len;
  109. + buffer_verify(buffer);
  110. + return 0;
  111. }
  112. /**
  113. --
  114. GitLab
  115. From df0acab3a077bd8ae015e3e8b4c71ff31b5900fe Mon Sep 17 00:00:00 2001
  116. From: Andreas Schneider <asn@cryptomilk.org>
  117. Date: Wed, 3 Jun 2020 10:11:21 +0200
  118. Subject: [PATCH 4/4] buffer: Add NULL check for 'buffer' argument
  119. Signed-off-by: Andreas Schneider <asn@cryptomilk.org>
  120. ---
  121. src/buffer.c | 4 ++++
  122. 1 file changed, 4 insertions(+)
  123. diff --git a/src/buffer.c b/src/buffer.c
  124. index 476bc135..ce12f491 100644
  125. --- a/src/buffer.c
  126. +++ b/src/buffer.c
  127. @@ -299,6 +299,10 @@ int ssh_buffer_reinit(struct ssh_buffer_struct *buffer)
  128. */
  129. int ssh_buffer_add_data(struct ssh_buffer_struct *buffer, const void *data, uint32_t len)
  130. {
  131. + if (buffer == NULL) {
  132. + return -1;
  133. + }
  134. +
  135. buffer_verify(buffer);
  136. if (data == NULL) {
  137. --
  138. GitLab