Browse Source

chat_msg: fix strstr on non-null-terminated blob/text data

chat_core_attachment_download: use sqlite3_column_text for null-term
on_msg_inserted: copy data to local null-term buf before strstr
Both caused b64_decode to misread body from garbage memory
topo_upd
evgeny 2 months ago
parent
commit
3665a9bc23
  1. 11
      src/chat/chat_msg.c

11
src/chat/chat_msg.c

@ -541,8 +541,11 @@ void on_msg_inserted(struct DB_SYNC_INSTANCE* si, uint64_t record_ts, const char
/* auto-download media if message contains media metadata */
if (data && len > 0 && author != g_cc.my_node_id) {
const char* ct = strstr(data, "\"ct\":\"");
const char* dpos = strstr(data, "\"d\":\"");
/* data from db_sync may not be null-terminated; copy to local buffer */
char buf[4096]; size_t blen = len < sizeof(buf) - 1 ? len : sizeof(buf) - 1;
memcpy(buf, data, blen); buf[blen] = '\0';
const char* ct = strstr(buf, "\"ct\":\"");
const char* dpos = strstr(buf, "\"d\":\"");
if (ct && dpos) {
const char* d_start = dpos + 5;
char body[4096]; size_t bi = 0;
@ -560,7 +563,7 @@ void on_msg_inserted(struct DB_SYNC_INSTANCE* si, uint64_t record_ts, const char
}
if (bfi == 0) snprintf(base_filename, sizeof(base_filename), "file");
const uint8_t* sig_field = strstr(data, "\"sig\":\"");
const uint8_t* sig_field = (const uint8_t*)strstr(buf, "\"sig\":\"");
uint8_t author_sig[64] = {0};
if (sig_field) {
/* read author_signature from DB — find by ts in on_msg_inserted we don't have sig
@ -616,7 +619,7 @@ void chat_core_attachment_download(const char* channel_id, int64_t msg_id) {
sqlite3_finalize(st);
return;
}
const uint8_t* jdata = (const uint8_t*)sqlite3_column_blob(st, 0);
const uint8_t* jdata = sqlite3_column_text(st, 0);
int jlen = sqlite3_column_bytes(st, 0);
int64_t db_ts = sqlite3_column_int64(st, 1);
const uint8_t* sig_blob = (const uint8_t*)sqlite3_column_blob(st, 2);

Loading…
Cancel
Save