From 6f2f85913c191ab9ddfb8fae781f5d66afccf3bf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?G=C3=BCnter=20Obiltschnig?= Date: Wed, 16 Apr 2025 09:15:33 +0200 Subject: [PATCH] fix(Net): A SEGV at Net/src/MultipartReader.cpp:164:1 #4915 (move assertion out of ctor) Upstream: https://github.com/pocoproject/poco/commit/6f2f85913c191ab9ddfb8fae781f5d66afccf3bf CVE: CVE-2025-6375 Signed-off-by: Thomas Perale --- Net/src/MultipartReader.cpp | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/Net/src/MultipartReader.cpp b/Net/src/MultipartReader.cpp index f3a2f2bba2..f4aa27dd86 100644 --- a/Net/src/MultipartReader.cpp +++ b/Net/src/MultipartReader.cpp @@ -36,7 +36,6 @@ MultipartStreamBuf::MultipartStreamBuf(std::istream& istr, const std::string& bo _boundary(boundary), _lastPart(false) { - poco_assert (!boundary.empty() && boundary.length() < STREAM_BUFFER_SIZE - 6); } @@ -47,7 +46,7 @@ MultipartStreamBuf::~MultipartStreamBuf() int MultipartStreamBuf::readFromDevice(char* buffer, std::streamsize length) { - poco_assert_dbg (length >= _boundary.length() + 6); + poco_assert (!_boundary.empty() && _boundary.length() < length - 6); static const int eof = std::char_traits::eof(); std::streambuf& buf = *_istr.rdbuf();