In lines 150-164, reads a length from the wire and then allocates that many bytes:
A malicious (or buggy) sender could send a very large value (e.g., ), causing to either fail (hopefully) or cause the receiver to allocate enormous amounts of memory (if is close to , wraps to 0 on overflow, and returns a valid pointer).
Impact
An attacker controlling the server or a man-in-the-middle could crash or exhaust memory on the client or vice versa.
Location
Suggested Fix
Add a maximum reasonable string length check:
Severity
Medium
Category
Security
## Description
In lines 150-164, reads a length from the wire and then allocates that many bytes:
A malicious (or buggy) sender could send a very large value (e.g., ), causing to either fail (hopefully) or cause the receiver to allocate enormous amounts of memory (if is close to , wraps to 0 on overflow, and returns a valid pointer).
## Impact
An attacker controlling the server or a man-in-the-middle could crash or exhaust memory on the client or vice versa.
## Location
## Suggested Fix
Add a maximum reasonable string length check:
## Severity
Medium
## Category
Security
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In lines 150-164, reads a length from the wire and then allocates that many bytes:
A malicious (or buggy) sender could send a very large value (e.g., ), causing to either fail (hopefully) or cause the receiver to allocate enormous amounts of memory (if is close to , wraps to 0 on overflow, and returns a valid pointer).
Impact
An attacker controlling the server or a man-in-the-middle could crash or exhaust memory on the client or vice versa.
Location
Suggested Fix
Add a maximum reasonable string length check:
Severity
Medium
Category
Security