New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix DoS #183 #184
Fix DoS #183 #184
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If you are concerned about this, you might also want to consider handling the case of language_id being empty, which would probably lead to the same segmentation fault?
|
I'm sorry, I just had another look at #183, and I don't believe this is a correct fix for the issue. Looking at the location of the crash (from #183), we got: I don't think the problem is that language is NULL, but that I'm not sure why |
|
@aburgm Sorry, I mislead the root cause of this crash.
So the proper solutions might be ...
|
This would be fine with me.
But this too. :) |
Instead of crashing, print the following warning message and ignore it when no current view exists. dbus should not be called when there is no document open. ** (gobby-0.5:78328): WARNING **: 10:01:05.468: No current view exists.
|
@aburgm I made a patch with the former one. |
|
@aburgm ping! |
|
Looks good to me, sorry for the delay! |
|
CVE-2020-35450 was assigned to this issue. |
Print warning message when language is a NULL pointer.