Rfc2253Parser silently accepted an empty RDN (no attributeTypeAndValue pair) 
instead of
throwing InvalidNameException. Rdn.getType()/getValue() then indexed an empty
internal list, throwing an uncaught IndexOutOfBoundsException instead of the 
documented
exception.

Two independent entry points:

Rdn("") - the original fuzzer-found crash.
LdapName("cn=x,") / LdapName.add("") - a string with a trailing , or ;, which 
never goes
through Rdn(String) at all (LdapName builds the RDN directly via Rfc2253Parser).

Add one check, rdn.size() == 0, throw InvalidNameException, placed in

Rfc2253Parser.doParse(Rdn) - the single method both paths funnel through.

Also add a regression check that "cn=a,,cn=b" still throws as before.




---------
- [x] I confirm that I make this contribution in accordance with the [OpenJDK 
Interim AI Policy](https://openjdk.org/legal/ai).

-------------

Commit messages:
 - 8391649: Rdn.getType()/getValue() throw uncaught IndexOutOfBoundsException 
on RDN with no attributeTypeAndValue

Changes: https://git.openjdk.org/jdk/pull/32648/files
  Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=32648&range=00
  Issue: https://bugs.openjdk.org/browse/JDK-8391649
  Stats: 19 lines in 2 files changed: 19 ins; 0 del; 0 mod
  Patch: https://git.openjdk.org/jdk/pull/32648.diff
  Fetch: git fetch https://git.openjdk.org/jdk.git pull/32648/head:pull/32648

PR: https://git.openjdk.org/jdk/pull/32648

Reply via email to