mirror of
https://github.com/znc/znc.git
synced 2026-08-07 09:22:55 +02:00
Fix a low impact directory traversal bug
A common pattern for checking directories in ZNC is the following: sAbsolutePath = CDir::ChangeDir(sAllowedPath, sFile); if (sAbsolutePath.Left(sAllowedPath.length()) != sAllowedPath) Error; But there is a problem: If sAllowedPath doesn't end with a slash, we are vulnerable to an attack. If e.g. sAllowedPath = "/foo/bar", then sFile = "../bartender" would result in sAbsolutePath = "/foo/bartender". Since this path does begin with sAllowedPath, the code allowed it. There shouldn't be any places where this can be exploited currently, but it is still a security bug (path traversal). git-svn-id: https://znc.svn.sourceforge.net/svnroot/znc/trunk@1569 726aef4b-f618-498e-8847-2d620e286838
This commit is contained in:
+2
-2
@@ -119,9 +119,9 @@ bool CHTTPSock::PrintFile(const CString& sFileName, CString sContentType) {
|
||||
if (!m_sDocRoot.empty()) {
|
||||
sFilePath.TrimLeft("/");
|
||||
|
||||
sFilePath = CDir::ChangeDir(m_sDocRoot, sFilePath, m_sDocRoot);
|
||||
sFilePath = CDir::CheckPathPrefix(m_sDocRoot, sFilePath, m_sDocRoot);
|
||||
|
||||
if (sFilePath.Left(m_sDocRoot.size()) != m_sDocRoot) {
|
||||
if (sFilePath.empty()) {
|
||||
PrintErrorPage(403, "Forbidden", "You don't have permission to access that file on this server.");
|
||||
DEBUG("THIS FILE: [" << sFilePath << "] does not live in ...");
|
||||
DEBUG("DOCUMENT ROOT: [" << m_sDocRoot << "]");
|
||||
|
||||
Reference in New Issue
Block a user