No limit in length of "Fullname" parameter results in DOS attack /memory corruption in ikus060/rdiffweb


Reported on

Sep 29th 2022

Proof of Concept

1)Go to endpoint . 
2)You will see a field called "Fullname"
3)Here you will see that there is no limit for the "Fullname" parameter that allows a user to to set a very long string as long as 1 million characters .
4)This may possibly result in a memory corruption/DOS attack.

Mitigation: There must be a fixed length for the "Fullname" parameter upto 128 characters

# Impact

Allows an attacker to set a "Fullname" with long string leading to memory corruption/possible DOS attack
We are processing your report and will contact the ikus060/rdiffweb team within 24 hours. a year ago
Patrik Dufresne assigned a CVE to this report a year ago
Patrik Dufresne validated this vulnerability a year ago
Nehal Pillai has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
Patrik Dufresne marked this as fixed in 2.5.0a3 with commit b62c47 a year ago
Patrik Dufresne has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation