mirror of
https://github.com/curl/curl.git
synced 2026-08-25 09:43:32 +03:00
escape: add a length check in curl_easy_escape
Only accept up to SIZE_MAX/16 input bytes. To avoid overflows, mistakes
and abuse.
Follow-up to 9bfc7f9234
Reported-by: Daniel Santos
Closes #20086
This commit is contained in:
parent
8636ad55df
commit
76e7d496b6
2 changed files with 4 additions and 2 deletions
|
|
@ -34,8 +34,7 @@ A-Z, 0-9, '-', '.', '_' or '~' are converted to their "URL escaped" version
|
||||||
constrained by its type, the returned string may not be altered.
|
constrained by its type, the returned string may not be altered.
|
||||||
|
|
||||||
If *length* is set to 0 (zero), curl_easy_escape(3) uses strlen() on the input
|
If *length* is set to 0 (zero), curl_easy_escape(3) uses strlen() on the input
|
||||||
*string* to find out the size. This function does not accept input strings
|
*string* to find out the size.
|
||||||
longer than **CURL_MAX_INPUT_LENGTH** (8 MB).
|
|
||||||
|
|
||||||
You must curl_free(3) the returned string when you are done with it.
|
You must curl_free(3) the returned string when you are done with it.
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -62,6 +62,9 @@ char *curl_easy_escape(CURL *data, const char *string, int inlength)
|
||||||
if(!length)
|
if(!length)
|
||||||
return curlx_strdup("");
|
return curlx_strdup("");
|
||||||
|
|
||||||
|
if(length > SIZE_MAX/16)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
curlx_dyn_init(&d, length * 3 + 1);
|
curlx_dyn_init(&d, length * 3 + 1);
|
||||||
|
|
||||||
while(length--) {
|
while(length--) {
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue