security: harden untrusted-input handling (issue #148)
All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 26s
CI Code / Code Coverage (pull_request) Successful in 3m29s
CI Code / Linux (debian) (pull_request) Successful in 5m13s
CI Code / Linux (ubuntu) (pull_request) Successful in 5m16s
CI Code / Linux (arch) (pull_request) Successful in 7m34s
All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 26s
CI Code / Code Coverage (pull_request) Successful in 3m29s
CI Code / Linux (debian) (pull_request) Successful in 5m13s
CI Code / Linux (ubuntu) (pull_request) Successful in 5m16s
CI Code / Linux (arch) (pull_request) Successful in 7m34s
T02: guard the receive-path handlers that dereferenced jid_create() without a NULL check — MUC join errors, subscribed/unsubscribed presence and, with silence.non-roster enabled, every incoming message. A stanza with a missing or malformed 'from' crashed the client (REQ-INP-01) T11: restrict /url open and /url save to http, https and aesgcm, so a received file:, javascript: or data: URL is refused (REQ-INP-06); spawn terminal-notifier through g_spawn_async with an argv instead of building a shell command for system() (REQ-INP-07); apply the XEP-0359 disco gate to MAM result ids, as live stanza-ids already do (REQ-INP-05); replace control and bidi-reordering characters in incoming message bodies with U+FFFD before they reach the terminal, the logs and the database, keeping LRM/RLM for legitimate RTL text (REQ-INP-08); cover JID part-length boundaries and invalid UTF-8 (REQ-INP-02) T10: replace strcpy/strcat/alloca and sprintf with g_strdup_printf and g_snprintf (REQ-MEM-03); allocate the OMEMO key buffers with g_malloc so a failed allocation cannot reach the following memcpy (REQ-MEM-04); remove the variable-length arrays and enforce -Werror=vla. Two of them were sized from remote input: the disco#info feature count and a chat message word length. The flag also caught a one-past-the-end write and a leak in the plugin autocompleter bindings (REQ-MEM-09)
This commit is contained in:
@@ -1955,7 +1955,10 @@ _cmd_ac_complete_params(ProfWin* window, const char* const input, gboolean previ
|
||||
}
|
||||
|
||||
size_t len = strlen(input);
|
||||
char parsed[len + 1];
|
||||
auto_char char* parsed = malloc(len + 1);
|
||||
if (!parsed) {
|
||||
return NULL;
|
||||
}
|
||||
size_t i = 0;
|
||||
while (i < len) {
|
||||
if (input[i] == ' ') {
|
||||
|
||||
@@ -9644,6 +9644,13 @@ cmd_url_open(ProfWin* window, const char* const command, gchar** args)
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
// URLs come from received messages: refuse file:, javascript:, data: etc.
|
||||
if (g_strcmp0(scheme, "http") != 0 && g_strcmp0(scheme, "https") != 0
|
||||
&& g_strcmp0(scheme, "aesgcm") != 0) {
|
||||
cons_show_error("URL scheme '%s' is not allowed, only http, https and aesgcm URLs can be opened.", scheme);
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
auto_gchar gchar* cmd_template = prefs_get_string(PREF_URL_OPEN_CMD);
|
||||
if (cmd_template == NULL) {
|
||||
cons_show_error("No default `url open` command found in executables preferences.");
|
||||
@@ -9689,6 +9696,13 @@ cmd_url_save(ProfWin* window, const char* const command, gchar** args)
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
// URLs come from received messages: refuse file:, javascript:, data: etc.
|
||||
if (g_strcmp0(scheme, "http") != 0 && g_strcmp0(scheme, "https") != 0
|
||||
&& g_strcmp0(scheme, "aesgcm") != 0) {
|
||||
cons_show_error("URL scheme '%s' is not allowed, only http, https and aesgcm URLs can be saved.", scheme);
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
auto_gchar gchar* cmd_template = prefs_get_string(PREF_URL_SAVE_CMD);
|
||||
if (cmd_template == NULL && (g_strcmp0(scheme, "http") == 0 || g_strcmp0(scheme, "https") == 0)) {
|
||||
_url_http_method(window, cmd_template, url, path);
|
||||
|
||||
Reference in New Issue
Block a user