fix(xmpp): treat disco#info result without 'from' as from the server
All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (ubuntu) (pull_request) Successful in 8m29s
CI Code / Linux (debian) (pull_request) Successful in 8m53s
CI Code / Code Coverage (pull_request) Successful in 9m7s
CI Code / Linux (arch) (pull_request) Successful in 12m11s
All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (ubuntu) (pull_request) Successful in 8m29s
CI Code / Linux (debian) (pull_request) Successful in 8m53s
CI Code / Code Coverage (pull_request) Successful in 9m7s
CI Code / Linux (arch) (pull_request) Successful in 12m11s
RFC 6120 §8.1.2.1: a stanza received over a c2s stream without a 'from' attribute must be treated as coming from the server itself. The on-connect disco#info handler passed the absent attribute as NULL into connection_features_received(), where g_str_hash() dereferenced the NULL key and crashed (remotely triggerable DoS on connect). Substitute connection_get_domain() at both disco#info handler boundaries, and make connection_features_received() and connection_get_features() NULL-safe as defense in depth. Add a stabber regression test answering the on-connect disco#info with a from-less result. Fixes #168
This commit is contained in:
@@ -173,6 +173,7 @@ main(int argc, char* argv[])
|
||||
PROF_FUNC_TEST(disco_info_without_name),
|
||||
PROF_FUNC_TEST(disco_items_without_name),
|
||||
PROF_FUNC_TEST(disco_info_service_unavailable),
|
||||
PROF_FUNC_TEST(disco_info_result_no_from),
|
||||
|
||||
/* Roster management - add/remove/rename contacts */
|
||||
PROF_FUNC_TEST(sends_new_item),
|
||||
|
||||
@@ -396,6 +396,35 @@ disco_items_without_name(void **state)
|
||||
prof_timeout_reset();
|
||||
}
|
||||
|
||||
void
|
||||
disco_info_result_no_from(void **state)
|
||||
{
|
||||
/*
|
||||
* Test that a disco#info result without a 'from' attribute is treated as
|
||||
* coming from the server itself (RFC 6120 §8.1.2.1). The on-connect
|
||||
* disco#info handler used to crash on such responses (issue #168).
|
||||
*/
|
||||
stbbr_for_query("http://jabber.org/protocol/disco#info",
|
||||
"<iq to='stabber@localhost/profanity' type='result'>"
|
||||
"<query xmlns='http://jabber.org/protocol/disco#info'>"
|
||||
"<identity category='server' type='im' name='NoFromServer'/>"
|
||||
"<feature var='urn:xmpp:ping'/>"
|
||||
"</query>"
|
||||
"</iq>"
|
||||
);
|
||||
|
||||
/* the on-connect disco#info gets the same from-less response */
|
||||
prof_connect();
|
||||
|
||||
prof_input("/disco info");
|
||||
|
||||
prof_timeout(10);
|
||||
/* client survived and attributed the response to the server */
|
||||
assert_true(prof_output_exact("Service discovery info for localhost"));
|
||||
assert_true(prof_output_regex("NoFromServer.*im.*server"));
|
||||
prof_timeout_reset();
|
||||
}
|
||||
|
||||
void
|
||||
disco_info_service_unavailable(void **state)
|
||||
{
|
||||
|
||||
@@ -17,3 +17,4 @@ void disco_info_multiple_identities(void **state);
|
||||
void disco_info_without_name(void **state);
|
||||
void disco_items_without_name(void **state);
|
||||
void disco_info_service_unavailable(void **state);
|
||||
void disco_info_result_no_from(void **state);
|
||||
|
||||
Reference in New Issue
Block a user