Commit 6488131 ("Fix RPC/SCGI security and crash bugs by @sirus20x6")
replaced std::vector<std::unique_ptr<const char>> storage with
std::vector<std::string> and returned back().c_str() to the xmlrpc-c
registry as the per-method server_info pointer.
This is unsafe for any method name short enough to be SSO-stored
(<= 15 chars on libstdc++): such a string keeps its buffer inside the
std::string object itself. When a later push_back reallocates the
vector and move-constructs the existing elements into a new buffer,
the previously returned c_str() pointers — captured by xmlrpc-c at
registration time — dangle into freed memory.
Because xmlrpc-c does not dereference server_info until a call
dispatches, the failure surfaces later as nondeterministic garbage
in fault strings, e.g.
faultString: Command "thod." does not exist. (load.start, log.xmlrpc, log.execute)
faultString: Command "in_rate" does not exist. (log.add_output)
faultString: Command "" does not exist. (log.open_file)
faultString: Command "+U" does not exist. (method.set_key)
Long-named methods (e.g. system.client_version at 21 chars) are
heap-allocated above the SSO threshold and escape the bug because
the heap buffer's address is preserved across the vector move.
Switch the storage to std::deque<std::string>: per [deque.modifiers]
push_back does not invalidate references to existing elements, so
the std::string objects do not move and the c_str() pointers handed
to xmlrpc-c remain valid for the program's lifetime. The body of
store_command_name is unchanged.
Fixes the use-after-free; preserves the std::string-based storage
the original commit aimed for.
RTorrent BitTorrent Client
Introduction
A ncurses-based command line torrent client for high performance.
To learn how to use rTorrent visit the Wiki.
Download the latest stable release
Related Projects
- https://github.com/rakshasa/rbedit: A dependency-free bencode editor.
Donate to rTorrent development
- Paypal
- Patreon
- SubscribeStar
- Bitcoin: 1MpmXm5AHtdBoDaLZstJw8nupJJaeKu8V8
- Ethereum: 0x9AB1e3C3d8a875e870f161b3e9287Db0E6DAfF78
- Litecoin: LdyaVR67LBnTf6mAT4QJnjSG2Zk67qxmfQ
- Cardano: addr1qytaslmqmk6dspltw06sp0zf83dh09u79j49ceh5y26zdcccgq4ph7nmx6kgmzeldauj43254ey97f3x4xw49d86aguqwfhlte
Help keep rTorrent development going by donating to its creator.
BUILDING
Jump into the github cloned directory
cd rtorrent
Install build dependencies
Install libtorrent with the same version rTorrent.
Generate configure scripts:
autoreconf -ivf
Optionally, generate man pages:
docbook2man rtorrent.1.xml
Man pages output to "doc/rtorrent.1".
RTorrent follows the development of libtorrent closely, and thus the versions must be in sync.
USAGE
Refer to User Guide: https://github.com/rakshasa/rtorrent/wiki/User-Guide
LICENSE
GNU GPL, see COPYING. "libtorrent/src/utils/sha_fast.{cc,h}" is originally from the Mozilla NSS and is under a triple license; MPL, LGPL and GPL. An exception to non-NSS code has been added for linking to OpenSSL as requested by Debian, though the author considers that library to be part of the Operative System and thus linking is allowed according to the GPL.
Use whatever fits your purpose, the code required to compile with Mozilla's NSS implementation of SHA1 has been retained and can be compiled if the user wishes to avoid using OpenSSL.
DEPENDENCIES
- libcurl >= 7.12.0
- libtorrent = (same version)
- ncurses
BUILD DEPENDENCIES
- libtoolize
- aclocal
- autoconf
- autoheader
- automake