|
5 | 5 | one entry cost exponential time and memory from a small file. The decoder now |
6 | 6 | limits each returned list to 65,536 values and returns |
7 | 7 | `MMDB_DECODER_LIMIT_ERROR` when an entry exceeds it. The largest real records |
8 | | - MaxMind produces decode a few hundred values. This follows the proposed Reader |
9 | | - Resource Limits guidance for the MaxMind DB specification. See |
10 | | - GHSA-hj94-g986-h9r7. |
11 | | -- Fixed a related payload-amplification denial of service. A crafted database |
12 | | - can point many times at one large value, so `MMDB_get_entry_data_list()` |
13 | | - returns a bounded number of nodes that together reference far more bytes than |
14 | | - the file holds. A caller that copies each node into a string then materializes |
15 | | - that amplified total. The decoder now also limits the total string and bytes |
16 | | - payload it exposes for a single entry to 2 MiB. Exceeding either new limit |
17 | | - returns `MMDB_DECODER_LIMIT_ERROR` and leaves the output list set to `NULL`. |
18 | | - These limits also protect the `languages` and `description` structures read by |
19 | | - `MMDB_open()`, where an over-limit structure is reported as |
20 | | - `MMDB_INVALID_METADATA_ERROR`. Both limits can be raised when rebuilding the |
21 | | - library with `-DMAXIMUM_DATA_STRUCTURE_VALUES=<values>` and |
| 8 | + MaxMind produces decode a few hundred values. This follows the Reader Resource |
| 9 | + Limits guidance in the MaxMind DB specification. See GHSA-hj94-g986-h9r7. |
| 10 | +- Fixed a related payload-amplification denial-of-service issue. A crafted |
| 11 | + database can point many times at one large value, so |
| 12 | + `MMDB_get_entry_data_list()` returns a bounded number of nodes that together |
| 13 | + reference far more bytes than the file holds. A caller that copies each node |
| 14 | + into a string then materializes that amplified total. The decoder now also |
| 15 | + limits the total string and bytes payload it exposes for a single entry to 2 |
| 16 | + MiB. Exceeding either new limit returns `MMDB_DECODER_LIMIT_ERROR` and leaves |
| 17 | + the output list set to `NULL`. These limits also protect the `languages` and |
| 18 | + `description` structures read by `MMDB_open()`, where an over-limit structure |
| 19 | + is reported as `MMDB_INVALID_METADATA_ERROR`. Both limits can be raised when |
| 20 | + rebuilding the library with `-DMAXIMUM_DATA_STRUCTURE_VALUES=<values>` and |
22 | 21 | `-DMAXIMUM_DATA_STRUCTURE_BYTES=<bytes>`. Applications using a packaged |
23 | 22 | library can retrieve individual values with `MMDB_get_value()` or |
24 | 23 | `MMDB_aget_value()` without expanding the complete structure. See |
|
0 commit comments