Blame SOURCES/freeradius-FR-GV-302-do-checks-based-on-pointers-not-on-decoded.patch

653d32
From 019e35431db17661aa1d74d995fd0315af9a8dbf Mon Sep 17 00:00:00 2001
653d32
From: "Alan T. DeKok" <aland@freeradius.org>
653d32
Date: Tue, 27 Jun 2017 21:54:10 -0400
653d32
Subject: [PATCH] FR-GV-302 - do checks based on pointers, not on decoded data
653d32
653d32
because decoded data may be empty
653d32
---
653d32
 src/lib/radius.c       | 10 +++++++++-
653d32
 src/tests/unit/rfc.txt | 12 ++++++++++++
653d32
 2 files changed, 21 insertions(+), 1 deletion(-)
653d32
653d32
diff --git a/src/lib/radius.c b/src/lib/radius.c
653d32
index ad6b15b46..7114e1650 100644
653d32
--- a/src/lib/radius.c
653d32
+++ b/src/lib/radius.c
653d32
@@ -2952,16 +2952,23 @@ static ssize_t data2vp_concat(TALLOC_CTX *ctx,
653d32
 	 *	don't care about walking off of the end of it.
653d32
 	 */
653d32
 	while (ptr < end) {
653d32
+		if (ptr[1] < 2) return -1;
653d32
+		if ((ptr + ptr[1]) > end) return -1;
653d32
+
653d32
 		total += ptr[1] - 2;
653d32
 
653d32
 		ptr += ptr[1];
653d32
 
653d32
+		if (ptr == end) break;
653d32
+
653d32
 		/*
653d32
 		 *	Attributes MUST be consecutive.
653d32
 		 */
653d32
 		if (ptr[0] != attr) break;
653d32
 	}
653d32
 
653d32
+	end = ptr;
653d32
+
653d32
 	vp = fr_pair_afrom_da(ctx, da);
653d32
 	if (!vp) return -1;
653d32
 
653d32
@@ -2974,7 +2981,7 @@ static ssize_t data2vp_concat(TALLOC_CTX *ctx,
653d32
 
653d32
 	total = 0;
653d32
 	ptr = start;
653d32
-	while (total < vp->vp_length) {
653d32
+	while (ptr < end) {
653d32
 		memcpy(p, ptr + 2, ptr[1] - 2);
653d32
 		p += ptr[1] - 2;
653d32
 		total += ptr[1] - 2;
653d32
@@ -2982,6 +2989,7 @@ static ssize_t data2vp_concat(TALLOC_CTX *ctx,
653d32
 	}
653d32
 
653d32
 	*pvp = vp;
653d32
+
653d32
 	return ptr - start;
653d32
 }
653d32
 
653d32
diff --git a/src/tests/unit/rfc.txt b/src/tests/unit/rfc.txt
653d32
index 00247940b..d870975e3 100644
653d32
--- a/src/tests/unit/rfc.txt
653d32
+++ b/src/tests/unit/rfc.txt
653d32
@@ -178,6 +178,18 @@ data Failed to parse IPv4 address string "256/8"
653d32
 attribute PMIP6-Home-IPv4-HoA = bob/8
653d32
 data Failed to parse IPv4 address string "bob/8"
653d32
 
653d32
+#
653d32
+#  A "concat" attribute, with no data
653d32
+#
653d32
+decode 89 02
653d32
+data PKM-SS-Cert = 0x
653d32
+
653d32
+#
653d32
+#  Or with weirdly formatted data
653d32
+#
653d32
+decode 89 03 ff 89 02 89 03 fe
653d32
+data PKM-SS-Cert = 0xfffe
653d32
+
653d32
 $INCLUDE tunnel.txt
653d32
 $INCLUDE errors.txt
653d32
 $INCLUDE extended.txt
653d32
-- 
653d32
2.13.2
653d32