]> git.ipfire.org Git - thirdparty/curl.git/commit
telnet: refuse IAC codes in content
authorDaniel Stenberg <daniel@haxx.se>
Sun, 21 Sep 2025 08:48:00 +0000 (10:48 +0200)
committerDaniel Stenberg <daniel@haxx.se>
Sun, 21 Sep 2025 21:00:02 +0000 (23:00 +0200)
commita72e1552f224f3785d8aafc9819cd4ad0821c01d
treec0cdc168c93531e4bfdf2c99adfcfdffd960c74e
parent989a274e45318b290b7ddf28d7562ff6ec0cba4a
telnet: refuse IAC codes in content

Ban the use of IAC (0xff) in telnet options set by the application. They
need to be escaped when sent but I can't see any valid reason for an
application to send them.

Of course, an application sending such data basically ask for trouble.

Reported in Joshua's sarif data

Closes #18657
lib/telnet.c