mirror of
https://github.com/rakshasa/rtorrent.git
synced 2026-10-05 13:49:21 +00:00
Bound JSON-RPC input by size and nesting depth
Enforce the nesting bound in one parse, capping allocation by depth, not input size.
This commit is contained in:
@@ -176,6 +176,7 @@ RpcManager::set_size_limit(uint64_t size) {
|
||||
throw torrent::input_error("XMLRPC size limit is too small to hold a request.");
|
||||
|
||||
m_xmlrpc.set_size_limit(size);
|
||||
m_jsonrpc.set_size_limit(size);
|
||||
}
|
||||
|
||||
void
|
||||
|
||||
Reference in New Issue
Block a user