|
@@ -0,0 +1,83 @@
|
|
|
+From af5b9a4a3945c52b940d5ac181ef51bb12011f1f Mon Sep 17 00:00:00 2001
|
|
|
+From: Patrick Griffis <pgriffis@igalia.com>
|
|
|
+Date: Wed, 12 Feb 2025 11:30:02 -0600
|
|
|
+Subject: [PATCH] headers: Handle parsing only newlines
|
|
|
+
|
|
|
+Closes #404
|
|
|
+Closes #407
|
|
|
+
|
|
|
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/libsoup/-/commit/af5b9a4a3945c52b940d5ac181ef51bb12011f1f]
|
|
|
+CVE: CVE-2025-32906
|
|
|
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
|
|
|
+---
|
|
|
+ libsoup/soup-headers.c | 4 ++--
|
|
|
+ tests/header-parsing-test.c | 13 ++++++++++++-
|
|
|
+ 2 files changed, 14 insertions(+), 3 deletions(-)
|
|
|
+
|
|
|
+diff --git a/libsoup/soup-headers.c b/libsoup/soup-headers.c
|
|
|
+index 9d6d00a3..52ef2ece 100644
|
|
|
+--- a/libsoup/soup-headers.c
|
|
|
++++ b/libsoup/soup-headers.c
|
|
|
+@@ -186,7 +186,7 @@ soup_headers_parse_request (const char *str,
|
|
|
+ /* RFC 2616 4.1 "servers SHOULD ignore any empty line(s)
|
|
|
+ * received where a Request-Line is expected."
|
|
|
+ */
|
|
|
+- while ((*str == '\r' || *str == '\n') && len > 0) {
|
|
|
++ while (len > 0 && (*str == '\r' || *str == '\n')) {
|
|
|
+ str++;
|
|
|
+ len--;
|
|
|
+ }
|
|
|
+@@ -371,7 +371,7 @@ soup_headers_parse_response (const char *str,
|
|
|
+ * after a response, which we then see prepended to the next
|
|
|
+ * response on that connection.
|
|
|
+ */
|
|
|
+- while ((*str == '\r' || *str == '\n') && len > 0) {
|
|
|
++ while (len > 0 && (*str == '\r' || *str == '\n')) {
|
|
|
+ str++;
|
|
|
+ len--;
|
|
|
+ }
|
|
|
+diff --git a/tests/header-parsing-test.c b/tests/header-parsing-test.c
|
|
|
+index 10ddb684..4faafbd6 100644
|
|
|
+--- a/tests/header-parsing-test.c
|
|
|
++++ b/tests/header-parsing-test.c
|
|
|
+@@ -6,10 +6,15 @@ typedef struct {
|
|
|
+ const char *name, *value;
|
|
|
+ } Header;
|
|
|
+
|
|
|
++/* These are not C strings to ensure going one byte over is not safe. */
|
|
|
+ static char unterminated_http_version[] = {
|
|
|
+ 'G','E','T',' ','/',' ','H','T','T','P','/','1', '0', '0', '.'
|
|
|
+ };
|
|
|
+
|
|
|
++static char only_newlines[] = {
|
|
|
++ '\n', '\n', '\n', '\n'
|
|
|
++};
|
|
|
++
|
|
|
+ static struct RequestTest {
|
|
|
+ const char *description;
|
|
|
+ const char *bugref;
|
|
|
+@@ -387,7 +392,6 @@ static struct RequestTest {
|
|
|
+ { { NULL } }
|
|
|
+ },
|
|
|
+
|
|
|
+- /* This couldn't be a C string as going one byte over would have been safe. */
|
|
|
+ { "Long HTTP version terminating at missing minor version", "https://gitlab.gnome.org/GNOME/libsoup/-/issues/404",
|
|
|
+ unterminated_http_version, sizeof (unterminated_http_version),
|
|
|
+ SOUP_STATUS_BAD_REQUEST,
|
|
|
+@@ -457,6 +461,13 @@ static struct RequestTest {
|
|
|
+ SOUP_STATUS_BAD_REQUEST,
|
|
|
+ NULL, NULL, -1,
|
|
|
+ { { NULL } }
|
|
|
++ },
|
|
|
++
|
|
|
++ { "Only newlines", NULL,
|
|
|
++ only_newlines, sizeof (only_newlines),
|
|
|
++ SOUP_STATUS_BAD_REQUEST,
|
|
|
++ NULL, NULL, -1,
|
|
|
++ { { NULL } }
|
|
|
+ }
|
|
|
+ };
|
|
|
+ static const int num_reqtests = G_N_ELEMENTS (reqtests);
|
|
|
+--
|
|
|
+GitLab
|
|
|
+
|