Emmanuel Lécharny created DIRAPI-438:
----------------------------------------

             Summary: Unbounded filter-nesting recursion causes 
StackOverflowError at decode time
                 Key: DIRAPI-438
                 URL: https://issues.apache.org/jira/browse/DIRAPI-438
             Project: Directory Client API
          Issue Type: Bug
    Affects Versions: 2.1.8
            Reporter: Emmanuel Lécharny
             Fix For: 2.1.9


Attacker opens a *TCP* connection to an *ApacheDS*-based server (no bind) and 
sends an _LDAPMessage_ whose _SearchRequest_ filter is 15,000 nested NOT 
filters followed by the attributes SEQUENCE; _transform()_ recurses 15,000 deep 
and _StackOverflowError_ escapes to the *MINA* processor thread shared by other 
connections. The same *PDU* sent by a hostile server crashes an ldap-api 
client's reader thread.

The *LDAP* grammar places no limit on search-filter nesting depth (neither 
_Asn1Decoder_ nor _LdapMessageContainer_ imposes a depth cap). 

*BER* decoding builds the _Filter_ tree iteratively, but when the attributes 
*SEQUENCE* tag arrives, _InitSearchRequestAttributeDescList.action()_ calls the 
private recursive _transform()_  — one stack frame per nesting level. ~7-15k 
levels (2-4 wire bytes each, i.e. a ~40-60 KB *PDU*) overflow a default thread 
stack. 

_StackOverflowError_ is an _Error_, so it bypasses the codec's 
_DecoderException_/_PROTOCOL_ERROR_ handling and propagates into the *MINA* I/O 
processor thread. 

Reachability is double-sided: the _SearchRequest_ is decoded pre-bind on the 
server side, and the client's _LdapMessageContainer<Message>_ uses the full 
grammar which accepts request-typed messages from the server.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to