Only allow IPv4 literals in strict form (#18656)
* Only allow IPv4 literals in strict form The strict form as defined in RFC 6943, section 3.1.1 only allows the dotted form ddd.ddd.ddd.ddd of IPv4 literals, where ddd is a one to three digit decimal number between 0 and 255. Until now octal numbers (with a leading zero) were interpreted as decimal numbers which has security implications, see CVE-2021-29922 and CVE-2021-29923. * Update lib/pure/net.nim Co-authored-by: Dominik Picheta <dominikpicheta@googlemail.com>
This commit is contained in:
parent
eb19db6595
commit
0d3af5454b
3 changed files with 106 additions and 44 deletions
|
|
@ -50,6 +50,41 @@ block: # parseIpAddress tests
|
|||
expect(ValueError):
|
||||
discard parseIpAddress("gggg:cdba:0000:0000:0000:0000:3257:9652")
|
||||
|
||||
block: # ipv4-compatible ipv6 address (embedded ipv4 address)
|
||||
check parseIpAddress("::ffff:10.0.0.23") == parseIpAddress("::ffff:0a00:0017")
|
||||
|
||||
block: # octal number in ipv4 address
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("010.8.8.8")
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("8.010.8.8")
|
||||
|
||||
block: # hexadecimal number in ipv4 address
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("0xc0.168.0.1")
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("192.0xa8.0.1")
|
||||
|
||||
block: # less than 4 numbers in ipv4 address
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("127.0.1")
|
||||
|
||||
block: # octal number in embedded ipv4 address
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("::ffff:010.8.8.8")
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("::ffff:8.010.8.8")
|
||||
|
||||
block: # hexadecimal number in embedded ipv4 address
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("::ffff:0xc0.168.0.1")
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("::ffff:192.0xa8.0.1")
|
||||
|
||||
block: # less than 4 numbers in embedded ipv4 address
|
||||
expect(ValueError):
|
||||
discard parseIpAddress("::ffff:127.0.1")
|
||||
|
||||
block: # "IpAddress/Sockaddr conversion"
|
||||
proc test(ipaddrstr: string) =
|
||||
var ipaddr_1 = parseIpAddress(ipaddrstr)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue