mirror of
https://github.com/xemu-project/xemu.git
synced 2024-11-24 03:59:52 +00:00
slirp: tftp: Relax filename format check
[ Applies on top of my recently posted slirp series. ] Allow tftp requests with filenames that do not start with a slash. Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com> Signed-off-by: Anthony Liguori <aliguori@us.ibm.com>
This commit is contained in:
parent
229609dd45
commit
74efd61a75
@ -284,11 +284,12 @@ static void tftp_handle_rrq(Slirp *slirp, struct tftp_t *tp, int pktlen)
|
|||||||
|
|
||||||
/* prepend tftp_prefix */
|
/* prepend tftp_prefix */
|
||||||
prefix_len = strlen(slirp->tftp_prefix);
|
prefix_len = strlen(slirp->tftp_prefix);
|
||||||
spt->filename = qemu_malloc(prefix_len + TFTP_FILENAME_MAX + 1);
|
spt->filename = qemu_malloc(prefix_len + TFTP_FILENAME_MAX + 2);
|
||||||
memcpy(spt->filename, slirp->tftp_prefix, prefix_len);
|
memcpy(spt->filename, slirp->tftp_prefix, prefix_len);
|
||||||
|
spt->filename[prefix_len] = '/';
|
||||||
|
|
||||||
/* get name */
|
/* get name */
|
||||||
req_fname = spt->filename + prefix_len;
|
req_fname = spt->filename + prefix_len + 1;
|
||||||
|
|
||||||
while (1) {
|
while (1) {
|
||||||
if (k >= TFTP_FILENAME_MAX || k >= pktlen) {
|
if (k >= TFTP_FILENAME_MAX || k >= pktlen) {
|
||||||
@ -315,7 +316,8 @@ static void tftp_handle_rrq(Slirp *slirp, struct tftp_t *tp, int pktlen)
|
|||||||
k += 6; /* skipping octet */
|
k += 6; /* skipping octet */
|
||||||
|
|
||||||
/* do sanity checks on the filename */
|
/* do sanity checks on the filename */
|
||||||
if (req_fname[0] != '/' || req_fname[strlen(req_fname) - 1] == '/' ||
|
if (!strncmp(req_fname, "../", 3) ||
|
||||||
|
req_fname[strlen(req_fname) - 1] == '/' ||
|
||||||
strstr(req_fname, "/../")) {
|
strstr(req_fname, "/../")) {
|
||||||
tftp_send_error(spt, 2, "Access violation", tp);
|
tftp_send_error(spt, 2, "Access violation", tp);
|
||||||
return;
|
return;
|
||||||
|
Loading…
Reference in New Issue
Block a user