Re: Serveez Information Leak Vulnerability
Austin James Gadient <[email protected]> Sun, 10 Nov 2019 01:07:27 +0000
| Newsgroups | gmane.network.serveez.bugs |
|---|---|
| Message-ID | <[email protected]> |
--_002_157334804697382649mitedu_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi Raimund,=0A= =0A= Ah sorry about that and no problem!=0A= =0A= I have attached a patch file that you should be able to apply from the serv= eez-0.2.2 directory.=0A= =0A= Let me know if you have any issues and thank you for your time!=0A= =0A= Best Regards,=0A= Austin=0A= ________________________________________=0A= From: Raimund 'Raimi' Jacob-Bl=F6dorn <[email protected]>=0A= Sent: Saturday, November 9, 2019 10:58 AM=0A= To: Austin James Gadient; [email protected]=0A= Subject: Re: [bug-serveez] Serveez Information Leak Vulnerability=0A= =0A= On 11/7/19 5:57 PM, Austin James Gadient wrote:=0A= =0A= Hello Austin!=0A= =0A= > Just following up. Have you had a chance to look at this?=0A= =0A= Well, I cannot do much with your Mac OS compilation attempts.=0A= =0A= I tried to diff your sources against the "next" branch of the serveez=0A= git repository but could not identify any change of yours.=0A= =0A= If I understand you correctly, it should be sufficient to make=0A= http->contentlength an unsigned int (and/or have an arbitrary cap somwhere)= .=0A= =0A= I am really sorry to have so little time to investigate. But if you send=0A= mit a simple diff I'll do my best to apply it.=0A= =0A= Greetings,=0A= =0A= Raimund=0A= =0A= --_002_157334804697382649mitedu_ Content-Type: application/octet-stream; name="http_contentlength.patch" Content-Description: http_contentlength.patch Content-Disposition: attachment; filename="http_contentlength.patch"; size=670; creation-date="Sun, 10 Nov 2019 01:06:52 GMT"; modification-date="Sun, 10 Nov 2019 01:06:52 GMT" Content-Transfer-Encoding: base64 ZGlmZiAtLWdpdCBhL3NyYy9odHRwLXNlcnZlci9odHRwLWNvcmUuaCBiL3NyYy9odHRwLXNlcnZl ci9odHRwLWNvcmUuaAppbmRleCA5ZDc2ODAyLi4zMmEwYzkzIDEwMDY0NAotLS0gYS9zcmMvaHR0 cC1zZXJ2ZXIvaHR0cC1jb3JlLmgKKysrIGIvc3JjL2h0dHAtc2VydmVyL2h0dHAtY29yZS5oCkBA IC03NSw3ICs3NSw3IEBAIHN0cnVjdCBodHRwX3NvY2tldAogewogICBodHRwX2NhY2hlX3QgKmNh Y2hlOyAgIC8qIGEgaHR0cCBmaWxlIGNhY2hlIHN0cnVjdHVyZSAqLwogICBjaGFyICoqcHJvcGVy dHk7ICAgICAgIC8qIHByb3BlcnR5IGxpc3Qgb2YgYSBodHRwIHJlcXVlc3QgKi8KLSAgaW50IGNv bnRlbnRsZW5ndGg7ICAgICAvKiB0aGUgY29udGVudCBsZW5ndGggZm9yIHRoZSBjZ2kgcGlwZSAq LworICBzaXplX3QgY29udGVudGxlbmd0aDsgICAgIC8qIHRoZSBjb250ZW50IGxlbmd0aCBmb3Ig dGhlIGNnaSBwaXBlICovCiAgIGludCBmaWxlbGVuZ3RoOyAgICAgICAgLyogY29udGVudCBsZW5n dGggZm9yIHRoZSBodHRwIGZpbGUgKi8KICAgaW50IGtlZXBhbGl2ZTsgICAgICAgICAvKiBob3cg bWFueSByZXF1ZXN0cyBsZWZ0IGZvciBhIGNvbm5lY3Rpb24gKi8KICAgb2ZmX3QgZmlsZW9mZnNl dDsgICAgICAvKiBmaWxlIG9mZnNldCB1c2VkIGJ5IHNlbmRmaWxlICovCg== --_002_157334804697382649mitedu_ Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KYnVnLXNlcnZl ZXogbWFpbGluZyBsaXN0CmJ1Zy1zZXJ2ZWV6QGdudS5vcmcKaHR0cHM6Ly9saXN0cy5nbnUub3Jn L21haWxtYW4vbGlzdGluZm8vYnVnLXNlcnZlZXoK --_002_157334804697382649mitedu_--