Emmanuel Lécharny created DIRAPI-438:
----------------------------------------
Summary: Unbounded filter-nesting recursion causes
StackOverflowError at decode time
Key: DIRAPI-438
URL: https://issues.apache.org/jira/browse/DIRAPI-438
Project: Directory Client API
Issue Type: Bug
Affects Versions: 2.1.8
Reporter: Emmanuel Lécharny
Fix For: 2.1.9
Attacker opens a *TCP* connection to an *ApacheDS*-based server (no bind) and
sends an _LDAPMessage_ whose _SearchRequest_ filter is 15,000 nested NOT
filters followed by the attributes SEQUENCE; _transform()_ recurses 15,000 deep
and _StackOverflowError_ escapes to the *MINA* processor thread shared by other
connections. The same *PDU* sent by a hostile server crashes an ldap-api
client's reader thread.
The *LDAP* grammar places no limit on search-filter nesting depth (neither
_Asn1Decoder_ nor _LdapMessageContainer_ imposes a depth cap).
*BER* decoding builds the _Filter_ tree iteratively, but when the attributes
*SEQUENCE* tag arrives, _InitSearchRequestAttributeDescList.action()_ calls the
private recursive _transform()_ — one stack frame per nesting level. ~7-15k
levels (2-4 wire bytes each, i.e. a ~40-60 KB *PDU*) overflow a default thread
stack.
_StackOverflowError_ is an _Error_, so it bypasses the codec's
_DecoderException_/_PROTOCOL_ERROR_ handling and propagates into the *MINA* I/O
processor thread.
Reachability is double-sided: the _SearchRequest_ is decoded pre-bind on the
server side, and the client's _LdapMessageContainer<Message>_ uses the full
grammar which accepts request-typed messages from the server.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]