git: b319c3d6ac7c - main - libfetch: Reject control characters in credentials
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 30 Sep 2026 16:55:47 UTC
The branch main has been updated by des:
URL: https://cgit.FreeBSD.org/src/commit/?id=b319c3d6ac7cf408b56fe745f718de6a324ec180
commit b319c3d6ac7cf408b56fe745f718de6a324ec180
Author: Dag-Erling Smørgrav <des@FreeBSD.org>
AuthorDate: 2026-09-30 16:54:33 +0000
Commit: Dag-Erling Smørgrav <des@FreeBSD.org>
CommitDate: 2026-09-30 16:54:33 +0000
libfetch: Reject control characters in credentials
If a URL contains credentials, check that neither the user name nor the
password contain control characters which might confuse the server,
especially in the FTP case.
MFC after: 1 week
Reviewed by: markj
Differential Revision: https://reviews.freebsd.org/D60008
---
lib/libfetch/fetch.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/lib/libfetch/fetch.c b/lib/libfetch/fetch.c
index 97fc04bb09a6..dd0603490674 100644
--- a/lib/libfetch/fetch.c
+++ b/lib/libfetch/fetch.c
@@ -347,7 +347,7 @@ struct url *
fetchParseURL(const char *URL)
{
char *doc;
- const char *p, *q;
+ const char *p, *q, *r;
struct url *u;
int i, n;
@@ -385,12 +385,18 @@ fetchParseURL(const char *URL)
q = fetch_pctdecode(u->user, URL, URL_USERLEN);
if (q == NULL)
goto ouch;
+ for (r = u->user; *r != '\0'; r++)
+ if (iscntrl((unsigned char)*r))
+ goto ouch;
/* password */
if (*q == ':') {
q = fetch_pctdecode(u->pwd, q + 1, URL_PWDLEN);
if (q == NULL)
goto ouch;
+ for (r = u->pwd; *r != '\0'; r++)
+ if (iscntrl((unsigned char)*r))
+ goto ouch;
}
p++;
} else {