mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-29 11:57:32 +09:00
Add extra check for path traversal sanity v2.
This commit is contained in:
parent
869e2c87e5
commit
093e83da1a
1 changed files with 4 additions and 1 deletions
|
|
@ -234,15 +234,18 @@ nsChromeRegistry::Canonify(nsIURL* aChromeURL)
|
||||||
aChromeURL->SetPath(path);
|
aChromeURL->SetPath(path);
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
// prevent directory traversals ("..")
|
|
||||||
// path is already unescaped once, but uris can get unescaped twice
|
// path is already unescaped once, but uris can get unescaped twice
|
||||||
const char* pos = path.BeginReading();
|
const char* pos = path.BeginReading();
|
||||||
const char* end = path.EndReading();
|
const char* end = path.EndReading();
|
||||||
|
if (*pos == '/' || *pos == ' ') {
|
||||||
|
return NS_ERROR_DOM_BAD_URI;
|
||||||
|
}
|
||||||
while (pos < end) {
|
while (pos < end) {
|
||||||
switch (*pos) {
|
switch (*pos) {
|
||||||
case ':':
|
case ':':
|
||||||
return NS_ERROR_DOM_BAD_URI;
|
return NS_ERROR_DOM_BAD_URI;
|
||||||
case '.':
|
case '.':
|
||||||
|
// prevent directory traversals ("..")
|
||||||
if (pos[1] == '.')
|
if (pos[1] == '.')
|
||||||
return NS_ERROR_DOM_BAD_URI;
|
return NS_ERROR_DOM_BAD_URI;
|
||||||
break;
|
break;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue