mirror of
https://github.com/curl/curl.git
synced 2026-07-21 18:47:16 +03:00
A CR or LF in the CURLOPT_FTP_ACCOUNT or CURLOPT_FTP_ALTERNATIVE_TO_USER string split the control-channel command line and smuggled a second FTP command. Reject a byte below 0x20 in both values before the command is built. Closes #22301
45 lines
913 B
XML
45 lines
913 B
XML
<?xml version="1.0" encoding="US-ASCII"?>
|
|
<testcase>
|
|
<info>
|
|
<keywords>
|
|
FTP
|
|
--ftp-alternative-to-user
|
|
</keywords>
|
|
</info>
|
|
# Server-side
|
|
<reply>
|
|
<servercmd>
|
|
REPLY USER 530 go away
|
|
</servercmd>
|
|
</reply>
|
|
|
|
# Client-side
|
|
<client>
|
|
<server>
|
|
ftp
|
|
</server>
|
|
<name>
|
|
FTP --ftp-alternative-to-user with embedded CRLF is rejected
|
|
</name>
|
|
# read the command from a config file so the raw CR LF reaches curl intact
|
|
<file name="%LOGDIR/test%TESTNUMBER.config">
|
|
ftp-alternative-to-user = "USER me\r\nDELE %TESTNUMBER"
|
|
</file>
|
|
<command>
|
|
ftp://%HOSTIP:%FTPPORT/%TESTNUMBER/ -K %LOGDIR/test%TESTNUMBER.config
|
|
</command>
|
|
</client>
|
|
|
|
# Verify data after the test has been "shot"
|
|
<verify>
|
|
# 43 - CURLE_BAD_FUNCTION_ARGUMENT
|
|
<errorcode>
|
|
43
|
|
</errorcode>
|
|
# the replacement command is rejected before it is sent, so the injected DELE
|
|
# command must never reach the server
|
|
<protocol crlf="yes">
|
|
USER anonymous
|
|
</protocol>
|
|
</verify>
|
|
</testcase>
|