From 865a131c7d557e68c965043d98c2eccae26deef8 Mon Sep 17 00:00:00 2001 From: squidadm Date: Sun, 17 May 2026 18:04:47 +1200 Subject: [PATCH] Improve parsing of certain FTP directory listing formats (#2408) (#2409) This surgical fix restricts parsing to the input buffer when the listing entry date in "TypeA" or "TypeB" formats is not followed by a filename. It does not improve rendering of listings with missing filenames or the overall quality of FTP listing parsing code. C strchr() always returns a non-nil pointer when given a NUL character, so its callers must be careful not to supply a NUL character if a "natural" one-of-the-regular-c-string-characters membership test is required. The bug was probably introduced in 1997 commit 3fdadc70 and then duplicated in 2017 commit 3d872090. Co-authored-by: Alex Rousskov Co-authored-by: Amos Jeffries Upstream: https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8 CVE: CVE-2026-47729 Signed-off-by: Thomas Perale --- src/clients/FtpGateway.cc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/clients/FtpGateway.cc b/src/clients/FtpGateway.cc index 164fd0e499c..e04bb603d96 100644 --- a/src/clients/FtpGateway.cc +++ b/src/clients/FtpGateway.cc @@ -622,7 +622,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags) // point after tokens[i+2] : copyFrom = buf + tokens[i + 2].pos + strlen(tokens[i + 2].token); if (flags.skip_whitespace) { - while (strchr(w_space, *copyFrom)) + while (*copyFrom && strchr(w_space, *copyFrom)) ++copyFrom; } else { /* Handle the following four formats: @@ -633,7 +633,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags) * Assuming a single space between date and filename * suggested by: Nathan.Bailey@cc.monash.edu.au and * Mike Battersby */ - if (strchr(w_space, *copyFrom)) + if (*copyFrom && strchr(w_space, *copyFrom)) ++copyFrom; }