https://bugzilla.redhat.com/show_bug.cgi?id=2520301
Bug ID: 2520301
Summary: CVE-2022-4993 perl-HTML-FormHandler:
HTML::FormHandler: Denial of Service via crafted error
messages [fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["64fbd072-c8ab-4fbc-bb2f-781bec245ab6"]}
Component: perl-HTML-FormHandler
Keywords: Security, SecurityTracking
Severity: high
Priority: high
Assignee: [email protected]
Reporter: [email protected]
QA Contact: [email protected]
CC: [email protected], [email protected]
Blocks: 2515449 (CVE-2022-4993)
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected
method dispatch and resource exhaustion because _apply_actions and add_error
use error message text built from request data as a Locale::Maketext bracket
notation template.
add_error hands its first argument to the language handle as the
Locale::Maketext message key, and the default handle's lexicon sets `_AUTO`, so
a string that is not a lexicon entry is compiled as a bracket notation template
instead of being looked up. In a bracket group the first token names a method
called on the language handle and the remaining tokens are its arguments.
Three kinds of text the library did not author reach that position.
_apply_actions installs a `$SIG{__WARN__}` handler that stores the warning text
in `$error_message`, and a captured warning survives a successful action, so a
field carrying a numeric transform turns `Argument "[sprintf,%50000000d,0]"
isn't numeric` into the template; a warning quotes the submitted value
verbatim, so the group is well formed and dispatches. `$error_message ||=
$tobj->validate($new_value)` takes a type constraint's own failure message,
which renders the rejected value through a partial dumper in bracket and comma
form (Devel::PartialDump when Moose can load it, Type::Tiny's own dumper
always), so a field with `apply => [ Str ]` given a parameter sent more than
once, which arrives as an array, gets `Reference ["a","b"] did not pass type
constraint "Str"` as its template, from a request that carries no bracket
character of its own. A coercion or transform exception reaches it the same
way. Beyond those, a validator whose message contains the field value puts that
value in the template directly, and add_error replaces the message list with
the contents of an arrayref first argument (`@message = @{$message[0]} if ref
$message[0] eq 'ARRAY'`), so a value arriving as an array fills the argument
slots from the same request as well.
A malformed group such as `[0]` makes the compile croak, and
HTML::FormHandler::I18N::maketext and add_error each re-raise that as a die, so
process() throws. A well formed group naming sprintf reaches CORE::sprintf with
an attacker chosen field width. Any caller that applies a type constraint or a
transform to an untrusted field, or whose validator passes an untrusted field
value to add_error, can be made to throw an unhandled exception out of
process(), or to allocate an arbitrary amount of memory in one request, and an
application whose language handle subclass defines side effecting public
methods makes those callable with attacker chosen arguments. The dumped type
constraint message is bounded to the exception, because both dumpers quote
non-numeric elements so the method slot is never an attacker chosen name. The
built-in messages pass fixed templates with the value in an argument slot,
where it stays inert, and the built-in field types attach explicit message
callbacks, so neither is affected.
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2515449
[Bug 2515449] CVE-2022-4993 perl-HTML-FormHandler: HTML::FormHandler: Denial of
Service via crafted error messages
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2520301
Report this comment as SPAM:
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202520301%23c0
--
_______________________________________________
perl-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it:
https://forge.fedoraproject.org/infra/tickets/issues/new