qemu-commits
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Qemu-commits] [COMMIT 74efd61] slirp: tftp: Relax filename format check


From: Anthony Liguori
Subject: [Qemu-commits] [COMMIT 74efd61] slirp: tftp: Relax filename format check
Date: Tue, 30 Jun 2009 00:57:43 -0000

From: Jan Kiszka <address@hidden>

[ Applies on top of my recently posted slirp series. ]

Allow tftp requests with filenames that do not start with a slash.

Signed-off-by: Jan Kiszka <address@hidden>
Signed-off-by: Anthony Liguori <address@hidden>

diff --git a/slirp/tftp.c b/slirp/tftp.c
index 3b8643b..082f5d0 100644
--- a/slirp/tftp.c
+++ b/slirp/tftp.c
@@ -284,11 +284,12 @@ static void tftp_handle_rrq(Slirp *slirp, struct tftp_t 
*tp, int pktlen)
 
   /* prepend tftp_prefix */
   prefix_len = strlen(slirp->tftp_prefix);
-  spt->filename = qemu_malloc(prefix_len + TFTP_FILENAME_MAX + 1);
+  spt->filename = qemu_malloc(prefix_len + TFTP_FILENAME_MAX + 2);
   memcpy(spt->filename, slirp->tftp_prefix, prefix_len);
+  spt->filename[prefix_len] = '/';
 
   /* get name */
-  req_fname = spt->filename + prefix_len;
+  req_fname = spt->filename + prefix_len + 1;
 
   while (1) {
     if (k >= TFTP_FILENAME_MAX || k >= pktlen) {
@@ -315,7 +316,8 @@ static void tftp_handle_rrq(Slirp *slirp, struct tftp_t 
*tp, int pktlen)
   k += 6; /* skipping octet */
 
   /* do sanity checks on the filename */
-  if (req_fname[0] != '/' || req_fname[strlen(req_fname) - 1] == '/' ||
+  if (!strncmp(req_fname, "../", 3) ||
+      req_fname[strlen(req_fname) - 1] == '/' ||
       strstr(req_fname, "/../")) {
       tftp_send_error(spt, 2, "Access violation", tp);
       return;




reply via email to

[Prev in Thread] Current Thread [Next in Thread]