mirror of
https://github.com/curl/curl.git
synced 2026-08-24 14:23:30 +03:00
ftp: reject illegal IP/port in PASV 227 response
... by using range checks. Among other things, this avoids an undefined behavior for a left shift that could happen on negative or very large values. Closes #1997 Detected by OSS-fuzz: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=3694
This commit is contained in:
parent
8351ab4510
commit
769647e714
2 changed files with 7 additions and 10 deletions
|
|
@ -30,13 +30,9 @@ ftp://%HOSTIP:%FTPPORT/237 --disable-epsv
|
|||
# certain hosts with buggy resolver code, the resulting address (192.0.2.127)
|
||||
# is from an address block that is guaranteed never to be assigned (RFC3330).
|
||||
<verify>
|
||||
# curl: (15) Can't resolve new host 1216.256.2.127:32639
|
||||
# 15 => CURLE_FTP_CANT_GET_HOST
|
||||
# some systems just don't fail on the illegal host name/address but instead
|
||||
# moves on and attempt to connect to... yes, to what?
|
||||
# 7= CURLE_COULDNT_CONNECT
|
||||
# 14 = CURLE_FTP_WEIRD_227_FORMAT
|
||||
<errorcode>
|
||||
15, 7
|
||||
14
|
||||
</errorcode>
|
||||
<protocol>
|
||||
USER anonymous
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue