diff options
author | Daniel Stenberg <daniel@haxx.se> | 2019-04-29 08:00:49 +0200 |
---|---|---|
committer | Daniel Stenberg <daniel@haxx.se> | 2019-04-29 08:02:44 +0200 |
commit | 5fc28510a4664f46459d9a40187d81cc08571e60 (patch) | |
tree | b6d15dac4952967aecf54af92f5a0f5ca10fcb66 /lib/setopt.c | |
parent | 2fe2da9f1a6b059f94c28e963032539790dbcae5 (diff) | |
download | curl-5fc28510a4664f46459d9a40187d81cc08571e60.tar.gz |
CURL_MAX_INPUT_LENGTH: largest acceptable string input size
This limits all accepted input strings passed to libcurl to be less than
CURL_MAX_INPUT_LENGTH (8000000) bytes, for these API calls:
curl_easy_setopt() and curl_url_set().
The 8000000 number is arbitrary picked and is meant to detect mistakes
or abuse, not to limit actual practical use cases. By limiting the
acceptable string lengths we also reduce the risk of integer overflows
all over.
NOTE: This does not apply to `CURLOPT_POSTFIELDS`.
Test 1559 verifies.
Closes #3805
Diffstat (limited to 'lib/setopt.c')
-rw-r--r-- | lib/setopt.c | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/lib/setopt.c b/lib/setopt.c index 594303eff..da9ed3bb1 100644 --- a/lib/setopt.c +++ b/lib/setopt.c @@ -61,6 +61,13 @@ CURLcode Curl_setstropt(char **charp, const char *s) if(s) { char *str = strdup(s); + if(str) { + size_t len = strlen(str); + if(len > CURL_MAX_INPUT_LENGTH) { + free(str); + return CURLE_BAD_FUNCTION_ARGUMENT; + } + } if(!str) return CURLE_OUT_OF_MEMORY; |