git: b319c3d6ac7c - main - libfetch: Reject control characters in credentials

From: Dag-Erling Smørgrav <des_at_FreeBSD.org>
Date: Wed, 30 Sep 2026 16:55:47 UTC
The branch main has been updated by des:

URL: https://cgit.FreeBSD.org/src/commit/?id=b319c3d6ac7cf408b56fe745f718de6a324ec180

commit b319c3d6ac7cf408b56fe745f718de6a324ec180
Author:     Dag-Erling Smørgrav <des@FreeBSD.org>
AuthorDate: 2026-09-30 16:54:33 +0000
Commit:     Dag-Erling Smørgrav <des@FreeBSD.org>
CommitDate: 2026-09-30 16:54:33 +0000

    libfetch: Reject control characters in credentials
    
    If a URL contains credentials, check that neither the user name nor the
    password contain control characters which might confuse the server,
    especially in the FTP case.
    
    MFC after:      1 week
    Reviewed by:    markj
    Differential Revision:  https://reviews.freebsd.org/D60008
---
 lib/libfetch/fetch.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/lib/libfetch/fetch.c b/lib/libfetch/fetch.c
index 97fc04bb09a6..dd0603490674 100644
--- a/lib/libfetch/fetch.c
+++ b/lib/libfetch/fetch.c
@@ -347,7 +347,7 @@ struct url *
 fetchParseURL(const char *URL)
 {
 	char *doc;
-	const char *p, *q;
+	const char *p, *q, *r;
 	struct url *u;
 	int i, n;
 
@@ -385,12 +385,18 @@ fetchParseURL(const char *URL)
 		q = fetch_pctdecode(u->user, URL, URL_USERLEN);
 		if (q == NULL)
 			goto ouch;
+		for (r = u->user; *r != '\0'; r++)
+			if (iscntrl((unsigned char)*r))
+				goto ouch;
 
 		/* password */
 		if (*q == ':') {
 			q = fetch_pctdecode(u->pwd, q + 1, URL_PWDLEN);
 			if (q == NULL)
 				goto ouch;
+			for (r = u->pwd; *r != '\0'; r++)
+				if (iscntrl((unsigned char)*r))
+					goto ouch;
 		}
 		p++;
 	} else {