mirror of
https://github.com/rakshasa/rtorrent.git
synced 2026-10-06 06:09:22 +00:00
efe258a137
Commit 6488131 ("Fix RPC/SCGI security and crash bugs by @sirus20x6")
replaced std::vector<std::unique_ptr<const char>> storage with
std::vector<std::string> and returned back().c_str() to the xmlrpc-c
registry as the per-method server_info pointer.
This is unsafe for any method name short enough to be SSO-stored
(<= 15 chars on libstdc++): such a string keeps its buffer inside the
std::string object itself. When a later push_back reallocates the
vector and move-constructs the existing elements into a new buffer,
the previously returned c_str() pointers — captured by xmlrpc-c at
registration time — dangle into freed memory.
Because xmlrpc-c does not dereference server_info until a call
dispatches, the failure surfaces later as nondeterministic garbage
in fault strings, e.g.
faultString: Command "thod." does not exist. (load.start, log.xmlrpc, log.execute)
faultString: Command "in_rate" does not exist. (log.add_output)
faultString: Command "" does not exist. (log.open_file)
faultString: Command "+U" does not exist. (method.set_key)
Long-named methods (e.g. system.client_version at 21 chars) are
heap-allocated above the SSO threshold and escape the bug because
the heap buffer's address is preserved across the vector move.
Switch the storage to std::deque<std::string>: per [deque.modifiers]
push_back does not invalidate references to existing elements, so
the std::string objects do not move and the c_str() pointers handed
to xmlrpc-c remain valid for the program's lifetime. The body of
store_command_name is unchanged.
Fixes the use-after-free; preserves the std::string-based storage
the original commit aimed for.
50 lines
1.0 KiB
C++
50 lines
1.0 KiB
C++
#include <deque>
|
|
#include "config.h"
|
|
|
|
#include "xmlrpc.h"
|
|
|
|
#include "parse_commands.h"
|
|
|
|
#include <cstring>
|
|
#include <torrent/exceptions.h>
|
|
|
|
namespace rpc {
|
|
|
|
std::deque<std::string> XmlRpc::m_command_names;
|
|
|
|
const char*
|
|
XmlRpc::store_command_name(const char* name) {
|
|
if (::strnlen(name, 1024 + 1) > 1024)
|
|
throw torrent::input_error("XMLRPC command name too long, limit is 8192 characters.");
|
|
|
|
for (const auto& itr : m_command_names) {
|
|
if (itr == name)
|
|
return itr.c_str();
|
|
}
|
|
|
|
m_command_names.push_back(name);
|
|
|
|
return m_command_names.back().c_str();
|
|
}
|
|
|
|
#ifndef HAVE_XMLRPC_C
|
|
#ifndef HAVE_XMLRPC_TINYXML2
|
|
|
|
void XmlRpc::initialize() {}
|
|
void XmlRpc::cleanup() {}
|
|
|
|
void XmlRpc::insert_command(const char*, const char*, const char*) {}
|
|
void XmlRpc::set_dialect(int) {}
|
|
|
|
bool XmlRpc::process(const char*, uint32_t, slot_write) { return false; }
|
|
|
|
int64_t XmlRpc::size_limit() { return 0; }
|
|
void XmlRpc::set_size_limit(uint64_t size) {}
|
|
|
|
bool XmlRpc::is_valid() const { return false; }
|
|
|
|
#endif
|
|
#endif
|
|
|
|
}
|