mirror of
https://github.com/rofl0r/proxychains-ng.git
synced 2026-10-06 20:40:22 +00:00
fix proxy_getaddrinfo crash when both node and hints are NULL
closes #620
This commit is contained in:
@@ -996,7 +996,7 @@ err_nn:
|
||||
goto err_nn;
|
||||
} else if(node) {
|
||||
af = ((struct sockaddr_in *) &space->sockaddr_space)->sin_family;
|
||||
} else if(!node && !(hints->ai_flags & AI_PASSIVE)) {
|
||||
} else if(!node && !(hints && (hints->ai_flags & AI_PASSIVE))) {
|
||||
af = ((struct sockaddr_in *) &space->sockaddr_space)->sin_family = AF_INET;
|
||||
memcpy(&((struct sockaddr_in *) &space->sockaddr_space)->sin_addr,
|
||||
"\177\0\0\1", 4);
|
||||
|
||||
25
tests/test_getaddrinfo_null_hints.c
Normal file
25
tests/test_getaddrinfo_null_hints.c
Normal file
@@ -0,0 +1,25 @@
|
||||
/*
|
||||
* NULL pointer dereference in proxy_getaddrinfo()
|
||||
* if node == NULL && hints == NULL.
|
||||
*/
|
||||
#define _POSIX_C_SOURCE 200112L
|
||||
#include <netdb.h>
|
||||
#include <signal.h>
|
||||
#include <stdio.h>
|
||||
#include <unistd.h>
|
||||
|
||||
static void on_crash(int sig) {
|
||||
fprintf(stderr, "POC_HIT: signal %d from getaddrinfo(NULL, \"80\", NULL, &res)\n", sig);
|
||||
fflush(stderr);
|
||||
_exit(0);
|
||||
}
|
||||
|
||||
int main(void) {
|
||||
struct addrinfo *res = 0;
|
||||
int rc;
|
||||
signal(SIGSEGV, on_crash);
|
||||
signal(SIGBUS, on_crash);
|
||||
rc = getaddrinfo(NULL, "80", NULL, &res);
|
||||
fprintf(stderr, "POC_MISS: getaddrinfo returned %d\n", rc);
|
||||
return 1;
|
||||
}
|
||||
Reference in New Issue
Block a user