Jens Geyer created THRIFT-6352:
----------------------------------

             Summary: Go TBinaryProtocol reads the name of an unversioned 
message header before checking its length
                 Key: THRIFT-6352
                 URL: https://issues.apache.org/jira/browse/THRIFT-6352
             Project: Thrift
          Issue Type: Bug
          Components: Go - Library
            Reporter: Jens Geyer


{{TBinaryProtocol.ReadMessageBegin}} reads the name of a message header that 
carries no version (the non-strict form) without first checking its length 
against the maximum message size. {{ReadString}} and the versioned header both 
do that check.

Fixed on master by 
[87c3ed6ce|https://github.com/apache/thrift/commit/87c3ed6ce80500f23b4210a30053288c75738e62]:
 the name length of an unversioned header is now held to the maximum message 
size before the name is read, as {{ReadString}} does.

Reported by Sylwester Lachiewicz.

_Drafted with AI assistance (Claude Opus 5); reviewed and posted by Jens Geyer._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to