[openssh-commits] [openssh] 02/02: upstream: sftp: be stricter in accepting paths returned by the

git+noreply at mindrot.org git+noreply at mindrot.org
Thu Oct 1 13:23:26 AEST 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit c07ea2180adebd6019a6ebdd89becb9d9f4b4897
Author: djm at openbsd.org <djm at openbsd.org>
AuthorDate: Thu Oct 1 03:11:49 2026 +0000

    upstream: sftp: be stricter in accepting paths returned by the
    
    server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used
    in some situations to decide the destination path for recursive transfers.
    
    Report and patch from Junghoon Cho
    
    OpenBSD-Commit-ID: ad357002a1b75c87113f01086a9f0c12c36082d8
---
 sftp-client.c |  5 +++--
 sftp.c        | 14 ++++++++++----
 2 files changed, 13 insertions(+), 6 deletions(-)

diff --git a/sftp-client.c b/sftp-client.c
index e001b53da..791b37c6d 100644
--- a/sftp-client.c
+++ b/sftp-client.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: sftp-client.c,v 1.187 2026/09/07 20:24:22 job Exp $ */
+/* $OpenBSD: sftp-client.c,v 1.188 2026/10/01 03:11:49 djm Exp $ */
 /*
  * Copyright (c) 2001-2004 Damien Miller <djm at openbsd.org>
  *
@@ -791,7 +791,8 @@ sftp_lsreaddir(struct sftp_conn *conn, const char *path, int print_flag,
 			 * These can be used to attack recursive ops
 			 * (e.g. send '../../../../etc/passwd')
 			 */
-			if (strpbrk(filename, SFTP_DIRECTORY_CHARS) != NULL) {
+			if (*filename == '\0' ||
+			    strpbrk(filename, SFTP_DIRECTORY_CHARS) != NULL) {
 				error("Server sent suspect path \"%s\" "
 				    "during readdir of \"%s\"", filename, path);
 			} else if (dir) {
diff --git a/sftp.c b/sftp.c
index 831e16d5e..ecbaefd61 100644
--- a/sftp.c
+++ b/sftp.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: sftp.c,v 1.259 2026/09/15 08:17:57 djm Exp $ */
+/* $OpenBSD: sftp.c,v 1.260 2026/10/01 03:11:49 djm Exp $ */
 /*
  * Copyright (c) 2001-2004 Damien Miller <djm at openbsd.org>
  *
@@ -699,9 +699,15 @@ process_get(struct sftp_conn *conn, const char *src, const char *dst,
 			goto out;
 		}
 
-		/* Special handling for dest of '..' */
-		if (strcmp(filename, "..") == 0)
-			filename = "."; /* Download to dest, not dest/.. */
+		/*
+		 * Special handling for destinations of '..' and remote roots.
+		 * In particular, never select the local root as an implicit
+		 * destination for a remote root.
+		 */
+		if (strcmp(filename, "..") == 0 ||
+		    (filename[0] != '\0' &&
+		    filename[strspn(filename, "/")] == '\0'))
+			filename = ".";
 
 		if (g.gl_matchc == 1 && dst) {
 			if (local_is_dir(dst)) {

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list