From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1MLAeY-0005FD-KG for qemu-devel@nongnu.org; Mon, 29 Jun 2009 02:47:46 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1MLAeT-0005DD-Um for qemu-devel@nongnu.org; Mon, 29 Jun 2009 02:47:46 -0400 Received: from [199.232.76.173] (port=48141 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1MLAeT-0005D7-Qp for qemu-devel@nongnu.org; Mon, 29 Jun 2009 02:47:41 -0400 Received: from fmmailgate02.web.de ([217.72.192.227]:43748) by monty-python.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1MLAeT-0007BD-89 for qemu-devel@nongnu.org; Mon, 29 Jun 2009 02:47:41 -0400 Message-ID: <4A486382.6040109@web.de> Date: Mon, 29 Jun 2009 08:47:30 +0200 From: Jan Kiszka MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enigD7C80CD187586F162E0E1F02" Sender: jan.kiszka@web.de Subject: [Qemu-devel] [PATCH] slirp: tftp: Relax filename format check List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Anthony Liguori Cc: qemu-devel This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enigD7C80CD187586F162E0E1F02 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: quoted-printable [ Applies on top of my recently posted slirp series. ] Allow tftp requests with filenames that do not start with a slash. Signed-off-by: Jan Kiszka --- slirp/tftp.c | 8 +++++--- 1 files changed, 5 insertions(+), 3 deletions(-) diff --git a/slirp/tftp.c b/slirp/tftp.c index 3b8643b..082f5d0 100644 --- a/slirp/tftp.c +++ b/slirp/tftp.c @@ -284,11 +284,12 @@ static void tftp_handle_rrq(Slirp *slirp, struct tf= tp_t *tp, int pktlen) =20 /* prepend tftp_prefix */ prefix_len =3D strlen(slirp->tftp_prefix); - spt->filename =3D qemu_malloc(prefix_len + TFTP_FILENAME_MAX + 1); + spt->filename =3D qemu_malloc(prefix_len + TFTP_FILENAME_MAX + 2); memcpy(spt->filename, slirp->tftp_prefix, prefix_len); + spt->filename[prefix_len] =3D '/'; =20 /* get name */ - req_fname =3D spt->filename + prefix_len; + req_fname =3D spt->filename + prefix_len + 1; =20 while (1) { if (k >=3D TFTP_FILENAME_MAX || k >=3D pktlen) { @@ -315,7 +316,8 @@ static void tftp_handle_rrq(Slirp *slirp, struct tftp= _t *tp, int pktlen) k +=3D 6; /* skipping octet */ =20 /* do sanity checks on the filename */ - if (req_fname[0] !=3D '/' || req_fname[strlen(req_fname) - 1] =3D=3D '= /' || + if (!strncmp(req_fname, "../", 3) || + req_fname[strlen(req_fname) - 1] =3D=3D '/' || strstr(req_fname, "/../")) { tftp_send_error(spt, 2, "Access violation", tp); return; --------------enigD7C80CD187586F162E0E1F02 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org iEYEARECAAYFAkpIY4oACgkQniDOoMHTA+l/NQCfRKxFKSErDmsUnFYFEJn2amD8 TxgAnAh7UgubVNypJNzHO4vSyodK0Hpr =LOf3 -----END PGP SIGNATURE----- --------------enigD7C80CD187586F162E0E1F02--