dxbjavid opened a new pull request, #3610:
URL: https://github.com/apache/thrift/pull/3610

   **Out-of-bounds read in THeaderTransport::readString**
   
   The info-header string length is bounded against the header section before 
`ptr` moves past the length varint, so the remaining count is overstated by the 
varint width and a negative length is never rejected; when a frame sizes its 
header section to fill the receive buffer, a crafted key length lets the 
following `str.assign` read a little past the end of the heap buffer. The 
pointer is now advanced past the varint before the check, a negative length is 
rejected, and the length is bounded against the corrected remaining, matching 
the negative-size rejection the protocol `readStringBody` already does. A 
regression case that crafts such a frame is added to `ThrifttReadCheckTests`.
   
   - [ ] Did you create an [Apache 
Jira](https://issues.apache.org/jira/projects/THRIFT/issues/) ticket?  
([Request account here](https://selfserve.apache.org/jira-account.html), not 
required for trivial changes)
   - [ ] If a ticket exists: Does your pull request title follow the pattern 
"THRIFT-NNNN: describe my issue"?
   - [x] Did you squash your changes to a single commit?  (not required, but 
preferred)
   - [x] Did you do your best to avoid breaking changes?  If one was needed, 
did you label the Jira ticket with "Breaking-Change"?
   - [ ] If your change does not involve any code, include `[skip ci]` anywhere 
in the commit message to free up build resources.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to