Author: emaste
Date: Tue Jan 15 15:35:14 2019
New Revision: 343043
URL: https://svnweb.freebsd.org/changeset/base/343043

Log:
  scp: disallow empty or current directory
  
  Obtained from:        OpenBSD scp.c 1.198
  Security:     CVE-2018-20685
  Sponsored by: The FreeBSD Foundation

Modified:
  head/crypto/openssh/scp.c

Modified: head/crypto/openssh/scp.c
==============================================================================
--- head/crypto/openssh/scp.c   Tue Jan 15 09:48:18 2019        (r343042)
+++ head/crypto/openssh/scp.c   Tue Jan 15 15:35:14 2019        (r343043)
@@ -1106,7 +1106,8 @@ sink(int argc, char **argv)
                        SCREWUP("size out of range");
                size = (off_t)ull;
 
-               if ((strchr(cp, '/') != NULL) || (strcmp(cp, "..") == 0)) {
+               if (*cp == '\0' || strchr(cp, '/') != NULL ||
+                   strcmp(cp, ".") == 0 || strcmp(cp, "..") == 0) {
                        run_err("error: unexpected filename: %s", cp);
                        exit(1);
                }
_______________________________________________
svn-src-head@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/svn-src-head
To unsubscribe, send any mail to "svn-src-head-unsubscr...@freebsd.org"

Reply via email to