19 months ago
fix UAF in davql select exec
/* * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER. * * Copyright 2016 Olaf Wintermann. All rights reserved. * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions are met: * * 1. Redistributions of source code must retain the above copyright * notice, this list of conditions and the following disclaimer. * * 2. Redistributions in binary form must reproduce the above copyright * notice, this list of conditions and the following disclaimer in the * documentation and/or other materials provided with the distribution. * * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE * POSSIBILITY OF SUCH DAMAGE. */ #include <stdio.h> #include <stdlib.h> #include "test.h" #include "base64.h" #include "crypto.h" int test_main(int argc, char **argv); #ifdef _WIN32 int wmain(int argc, wchar_t **argv) { return test_main(1, "davtest"); } #else int main(int argc, char **argv) { return test_main(argc, argv); } #endif int test_main(int argc, char **argv) { printf("libidav tests\n"); printf("-------------\n\n"); UcxTestSuite* suite = ucx_test_suite_new(); ucx_test_register(suite, test_util_base64decode); ucx_test_register(suite, test_util_base64decode_len); ucx_test_register(suite, test_util_base64encode); ucx_test_register(suite, test_util_decrypt_str_k); ucx_test_register(suite, test_util_encrypt_str_k); ucx_test_register(suite, test_crypto_buffer); ucx_test_register(suite, test_crypto_stream); ucx_test_register(suite, test_dav_pw2key); ucx_test_run(suite, stdout); fflush(stdout); ucx_test_suite_free(suite); return 0; }