[openssh-commits] [openssh] 02/02: upstream: sftp: be stricter in accepting paths returned by the
git+noreply at mindrot.org
git+noreply at mindrot.org
Thu Oct 1 13:23:26 AEST 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
commit c07ea2180adebd6019a6ebdd89becb9d9f4b4897
Author: djm at openbsd.org <djm at openbsd.org>
AuthorDate: Thu Oct 1 03:11:49 2026 +0000
upstream: sftp: be stricter in accepting paths returned by the
server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used
in some situations to decide the destination path for recursive transfers.
Report and patch from Junghoon Cho
OpenBSD-Commit-ID: ad357002a1b75c87113f01086a9f0c12c36082d8
---
sftp-client.c | 5 +++--
sftp.c | 14 ++++++++++----
2 files changed, 13 insertions(+), 6 deletions(-)
diff --git a/sftp-client.c b/sftp-client.c
index e001b53da..791b37c6d 100644
--- a/sftp-client.c
+++ b/sftp-client.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: sftp-client.c,v 1.187 2026/09/07 20:24:22 job Exp $ */
+/* $OpenBSD: sftp-client.c,v 1.188 2026/10/01 03:11:49 djm Exp $ */
/*
* Copyright (c) 2001-2004 Damien Miller <djm at openbsd.org>
*
@@ -791,7 +791,8 @@ sftp_lsreaddir(struct sftp_conn *conn, const char *path, int print_flag,
* These can be used to attack recursive ops
* (e.g. send '../../../../etc/passwd')
*/
- if (strpbrk(filename, SFTP_DIRECTORY_CHARS) != NULL) {
+ if (*filename == '\0' ||
+ strpbrk(filename, SFTP_DIRECTORY_CHARS) != NULL) {
error("Server sent suspect path \"%s\" "
"during readdir of \"%s\"", filename, path);
} else if (dir) {
diff --git a/sftp.c b/sftp.c
index 831e16d5e..ecbaefd61 100644
--- a/sftp.c
+++ b/sftp.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: sftp.c,v 1.259 2026/09/15 08:17:57 djm Exp $ */
+/* $OpenBSD: sftp.c,v 1.260 2026/10/01 03:11:49 djm Exp $ */
/*
* Copyright (c) 2001-2004 Damien Miller <djm at openbsd.org>
*
@@ -699,9 +699,15 @@ process_get(struct sftp_conn *conn, const char *src, const char *dst,
goto out;
}
- /* Special handling for dest of '..' */
- if (strcmp(filename, "..") == 0)
- filename = "."; /* Download to dest, not dest/.. */
+ /*
+ * Special handling for destinations of '..' and remote roots.
+ * In particular, never select the local root as an implicit
+ * destination for a remote root.
+ */
+ if (strcmp(filename, "..") == 0 ||
+ (filename[0] != '\0' &&
+ filename[strspn(filename, "/")] == '\0'))
+ filename = ".";
if (g.gl_matchc == 1 && dst) {
if (local_is_dir(dst)) {
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list