]> git.mxchange.org Git - quix0rs-gnu-social.git/commitdiff
OpenID extlib updated: Fixes CVE-2014-8150
authorMikael Nordfeldth <mmn@hethane.se>
Sun, 2 Aug 2015 11:39:38 +0000 (13:39 +0200)
committerMikael Nordfeldth <mmn@hethane.se>
Sun, 2 Aug 2015 11:39:38 +0000 (13:39 +0200)
extlib/Auth/OpenID/URINorm.php

index c051b550aa1b1e3d339cb7110f6bc80ddedaa8d8..32e84588dbe77f55f7daeb849163bb946a26c40c 100644 (file)
@@ -93,7 +93,17 @@ function Auth_OpenID_pct_encoded_replace_unreserved($mo)
 
 function Auth_OpenID_pct_encoded_replace($mo)
 {
-    return chr(intval($mo[1], 16));
+    $code = intval($mo[1], 16);
+
+    // Prevent request splitting by ignoring newline and space characters
+    if($code === 0xA || $code === 0xD || $code === ord(' '))
+    {
+        return $mo[0];
+    }
+    else
+    {
+        return chr($code);
+    }
 }
 
 function Auth_OpenID_remove_dot_segments($path)