mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 10:31:33 -04:00
ipvs: fix integer overflow in ftp helper port/address parsing
ip_vs_ftp_get_addrport() accumulates decimal digits into a __u16 (hport) and into unsigned char (p[]) without checking for overflow. A crafted FTP PASV/EPSV response with an over-long port or address octet wraps the value, so the helper configures the data connection with a truncated port/address. The netfilter conntrack FTP helper had the same defect, fixed in commit2b413fc689("netfilter: nf_conntrack_ftp: avoid u16 overflows"). Apply the equivalent fix here: widen the port accumulator to u32 and reject values above 65535, and reject address octets above 255. Fixes:1da177e4c3("Linux-2.6.12-rc2") Signed-off-by: Joas Antonio dos Santos <joasantonio108@gmail.com> Acked-by: Julian Anastasov <ja@ssi.bg> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
committed by
Pablo Neira Ayuso
parent
1e3b9e1c77
commit
e625a9477d
@@ -102,7 +102,7 @@ static int ip_vs_ftp_get_addrport(char *data, char *data_limit,
|
||||
char *s, c;
|
||||
unsigned char p[6];
|
||||
char edelim;
|
||||
__u16 hport;
|
||||
__u32 hport;
|
||||
int i = 0;
|
||||
|
||||
if (data_limit - data < plen) {
|
||||
@@ -144,7 +144,11 @@ static int ip_vs_ftp_get_addrport(char *data, char *data_limit,
|
||||
return -1;
|
||||
c = *data;
|
||||
if (isdigit(c)) {
|
||||
p[i] = p[i]*10 + c - '0';
|
||||
unsigned int val = p[i] * 10 + c - '0';
|
||||
|
||||
if (val > 255)
|
||||
return -1;
|
||||
p[i] = val;
|
||||
} else if (c == ',' && i < 5) {
|
||||
i++;
|
||||
p[i] = 0;
|
||||
@@ -222,6 +226,8 @@ static int ip_vs_ftp_get_addrport(char *data, char *data_limit,
|
||||
if (!isdigit(*s))
|
||||
break;
|
||||
hport = hport * 10 + *s - '0';
|
||||
if (hport > 65535)
|
||||
return -1;
|
||||
}
|
||||
if (s == data_limit || !hport || *s != edelim)
|
||||
return -1;
|
||||
|
||||
Reference in New Issue
Block a user