Emmanuel Lécharny created DIRAPI-441:
----------------------------------------

             Summary: Malformed base64 in DSML document throws uncaught 
IllegalArgumentException
                 Key: DIRAPI-441
                 URL: https://issues.apache.org/jira/browse/DIRAPI-441
             Project: Directory Client API
          Issue Type: Bug
    Affects Versions: 2.1.8
            Reporter: Emmanuel Lécharny
             Fix For: 2.1.9


A remote user submits a _batchRequest_ with _<value 
xsi:type="xsd:base64Binary">!!!not-base64!!!</value>_
_Base64.decode_ throws _IllegalArgumentException_ past all handlers, 
_processDSML_ throws, no _batchResponse_ is written, and repeating the request 
cheaply kills every processing thread/request. A hostile server's *DSML* 
responses crash client-side consumers the same way.




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to