diff options
author | Nick Mathewson <nickm@torproject.org> | 2017-07-05 13:43:31 -0400 |
---|---|---|
committer | Nick Mathewson <nickm@torproject.org> | 2017-07-05 13:43:31 -0400 |
commit | 5434b2451e73bd4cd5eb62fb5e6c468eeee70153 (patch) | |
tree | de70e85c16f53fdbe3c7c12031e3b3ae3b79dec1 | |
parent | 0f97f963e3c267852a3f28538c5ddb196ce0bb42 (diff) | |
parent | 546f5b364bd8198b23b1ad4e66790eb1ce9b438e (diff) | |
download | tor-5434b2451e73bd4cd5eb62fb5e6c468eeee70153.tar.gz tor-5434b2451e73bd4cd5eb62fb5e6c468eeee70153.zip |
Merge branch 'maint-0.3.0' into maint-0.3.1
-rw-r--r-- | changes/bug22789 | 6 | ||||
-rw-r--r-- | src/common/compat.c | 8 | ||||
-rw-r--r-- | src/test/test_addr.c | 9 |
3 files changed, 21 insertions, 2 deletions
diff --git a/changes/bug22789 b/changes/bug22789 new file mode 100644 index 0000000000..dc9fa29811 --- /dev/null +++ b/changes/bug22789 @@ -0,0 +1,6 @@ + o Major bugfixes (openbsd, denial-of-service): + - Avoid an assertion failure bug affecting our implementation of + inet_pton(AF_INET6) on certain OpenBSD systems whose strtol() + handling of "0xfoo" differs from what we had expected. + Fixes bug 22789; bugfix on 0.2.3.8-alpha. + diff --git a/src/common/compat.c b/src/common/compat.c index acd2df7c6e..fb712f26d9 100644 --- a/src/common/compat.c +++ b/src/common/compat.c @@ -2598,8 +2598,12 @@ tor_inet_pton(int af, const char *src, void *dst) char *next; ssize_t len; long r = strtol(src, &next, 16); - tor_assert(next != NULL); - tor_assert(next != src); + if (next == NULL || next == src) { + /* The 'next == src' error case can happen on versions of openbsd + * where treats "0xfoo" as an error, rather than as "0" followed by + * "xfoo". */ + return 0; + } len = *next == '\0' ? eow - src : next - src; if (len > 4) diff --git a/src/test/test_addr.c b/src/test/test_addr.c index daa8e74189..2f591bdfe7 100644 --- a/src/test/test_addr.c +++ b/src/test/test_addr.c @@ -376,6 +376,15 @@ test_addr_ip6_helpers(void *arg) test_pton6_bad("1.2.3.4"); test_pton6_bad(":1.2.3.4"); test_pton6_bad(".2.3.4"); + /* Regression tests for 22789. */ + test_pton6_bad("0xfoo"); + test_pton6_bad("0x88"); + test_pton6_bad("0xyxxy"); + test_pton6_bad("0XFOO"); + test_pton6_bad("0X88"); + test_pton6_bad("0XYXXY"); + test_pton6_bad("0x"); + test_pton6_bad("0X"); /* test internal checking */ test_external_ip("fbff:ffff::2:7", 0); |