diff options
author | djm@openbsd.org <djm@openbsd.org> | 2019-07-09 04:15:00 +0000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2019-07-09 14:20:15 +1000 |
commit | 5b2b79ff7c057ee101518545727ed3023372891d (patch) | |
tree | 73b104b883b87dbd00954199a16c1238d2a71299 | |
parent | eb0b51dac408fadd1fd13fa6d726ab8fdfcc4152 (diff) | |
download | openssh-git-5b2b79ff7c057ee101518545727ed3023372891d.tar.gz |
upstream: cap the number of permiopen/permitlisten directives we're
willing to parse on a single authorized_keys line; ok deraadt@
OpenBSD-Commit-ID: a43a752c2555d26aa3fc754805a476f6e3e30f46
-rw-r--r-- | auth-options.c | 4 | ||||
-rw-r--r-- | auth-options.h | 5 |
2 files changed, 6 insertions, 3 deletions
diff --git a/auth-options.c b/auth-options.c index 4923a83b..51422188 100644 --- a/auth-options.c +++ b/auth-options.c @@ -1,4 +1,4 @@ -/* $OpenBSD: auth-options.c,v 1.85 2019/06/27 18:03:37 deraadt Exp $ */ +/* $OpenBSD: auth-options.c,v 1.86 2019/07/09 04:15:00 djm Exp $ */ /* * Copyright (c) 2018 Damien Miller <djm@mindrot.org> * @@ -320,7 +320,7 @@ handle_permit(const char **optsp, int allow_bare_port, size_t npermits = *npermitsp; const char *errstr = "unknown error"; - if (npermits > INT_MAX) { + if (npermits > SSH_AUTHOPT_PERMIT_MAX) { *errstrp = "too many permission directives"; return -1; } diff --git a/auth-options.h b/auth-options.h index 0462983b..14cbfa49 100644 --- a/auth-options.h +++ b/auth-options.h @@ -1,4 +1,4 @@ -/* $OpenBSD: auth-options.h,v 1.27 2018/06/06 18:23:32 djm Exp $ */ +/* $OpenBSD: auth-options.h,v 1.28 2019/07/09 04:15:00 djm Exp $ */ /* * Copyright (c) 2018 Damien Miller <djm@mindrot.org> @@ -22,6 +22,9 @@ struct passwd; struct sshkey; +/* Maximum number of permitopen/permitlisten directives to accept */ +#define SSH_AUTHOPT_PERMIT_MAX 4096 + /* * sshauthopt represents key options parsed from authorized_keys or * from certificate extensions/options. |