Only allow IPv4 literals in strict form (#18656)

* Only allow IPv4 literals in strict form

The strict form as defined in RFC 6943, section 3.1.1 only allows the dotted
form ddd.ddd.ddd.ddd of IPv4 literals, where ddd is a one to three digit decimal
number between 0 and 255. Until now octal numbers (with a leading zero) were
interpreted as decimal numbers which has security implications, see
CVE-2021-29922 and CVE-2021-29923.

* Update lib/pure/net.nim

Co-authored-by: Dominik Picheta <dominikpicheta@googlemail.com>
This commit is contained in:
Christian Ulrich 2021-08-08 20:11:07 +02:00 • committed by GitHub
commit 0d3af5454b
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
3 changed files with 106 additions and 44 deletions

View file

@ -50,6 +50,41 @@ block: # parseIpAddress tests
expect(ValueError):
discard parseIpAddress("gggg:cdba:0000:0000:0000:0000:3257:9652")
block: # ipv4-compatible ipv6 address (embedded ipv4 address)
check parseIpAddress("::ffff:10.0.0.23") == parseIpAddress("::ffff:0a00:0017")
block: # octal number in ipv4 address
expect(ValueError):
discard parseIpAddress("010.8.8.8")
expect(ValueError):
discard parseIpAddress("8.010.8.8")
block: # hexadecimal number in ipv4 address
expect(ValueError):
discard parseIpAddress("0xc0.168.0.1")
expect(ValueError):
discard parseIpAddress("192.0xa8.0.1")
block: # less than 4 numbers in ipv4 address
expect(ValueError):
discard parseIpAddress("127.0.1")
block: # octal number in embedded ipv4 address
expect(ValueError):
discard parseIpAddress("::ffff:010.8.8.8")
expect(ValueError):
discard parseIpAddress("::ffff:8.010.8.8")
block: # hexadecimal number in embedded ipv4 address
expect(ValueError):
discard parseIpAddress("::ffff:0xc0.168.0.1")
expect(ValueError):
discard parseIpAddress("::ffff:192.0xa8.0.1")
block: # less than 4 numbers in embedded ipv4 address
expect(ValueError):
discard parseIpAddress("::ffff:127.0.1")
block: # "IpAddress/Sockaddr conversion"
proc test(ipaddrstr: string) =
var ipaddr_1 = parseIpAddress(ipaddrstr)