Skip to content

bound WMS exception response copy to result_size in msDrawWMSLayerLow#7578

Open
nvxbug wants to merge 1 commit into
MapServer:mainfrom
nvxbug:wms-exception-response-bound
Open

bound WMS exception response copy to result_size in msDrawWMSLayerLow#7578
nvxbug wants to merge 1 commit into
MapServer:mainfrom
nvxbug:wms-exception-response-bound

Conversation

@nvxbug

@nvxbug nvxbug commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

When a cascaded WMS server returns an XML exception, msDrawWMSLayerLow copies the response into a fixed szBuf with strlcpy(szBuf, result_data, MS_BUFFER_LENGTH). result_data is assembled in msHTTPWriteFct by memcpy of exactly result_size bytes and is never NUL-terminated (the +10000 slack from msSmallMalloc is uninitialized heap). strlcpy scans the source for a NUL to compute its length, so it walks past result_size into uninitialized or adjacent heap, and those bytes then land in the msSetError/msDebug message. A malicious or compromised upstream server sending a NUL-free text/xml body on the default in-memory path triggers it.

Copy result_size bytes and terminate explicitly, the way the sibling result_data consumers a few lines down already do. Keeping the length bound at the copy site is the only place that knows the real byte count, since the buffer past result_size is not part of the response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant