]> git.ipfire.org Git - thirdparty/tor.git/commitdiff
TROVE-2017-005: Fix assertion failure in connection_edge_process_relay_cell
authorDavid Goulet <dgoulet@torproject.org>
Mon, 5 Jun 2017 15:11:42 +0000 (11:11 -0400)
committerNick Mathewson <nickm@torproject.org>
Thu, 8 Jun 2017 13:21:10 +0000 (09:21 -0400)
On an hidden service rendezvous circuit, a BEGIN_DIR could be sent
(maliciously) which would trigger a tor_assert() because
connection_edge_process_relay_cell() thought that the circuit is an
or_circuit_t but is an origin circuit in reality.

Fixes #22494

Reported-by: Roger Dingledine <arma@torproject.org>
Signed-off-by: David Goulet <dgoulet@torproject.org>
changes/trove-2017-005 [new file with mode: 0644]
src/or/relay.c

diff --git a/changes/trove-2017-005 b/changes/trove-2017-005
new file mode 100644 (file)
index 0000000..cebb013
--- /dev/null
@@ -0,0 +1,7 @@
+  o Major bugfixes (hidden service, relay, security):
+    - Fix an assertion failure caused by receiving a BEGIN_DIR cell on
+      a hidden service rendezvous circuit. Fixes bug 22494, tracked as
+      TROVE-2017-005 and CVE-2017-0376; bugfix on 0.2.2.1-alpha. Found
+      by armadev.
+
+
index 7f06c6e14596fd421aa0f0a5601356479d4fcd0e..59b79f95c9772da8d9a1f12b28c3a67b82f5bf2a 100644 (file)
@@ -1297,7 +1297,8 @@ connection_edge_process_relay_cell(cell_t *cell, circuit_t *circ,
                "Begin cell for known stream. Dropping.");
         return 0;
       }
-      if (rh.command == RELAY_COMMAND_BEGIN_DIR) {
+      if (rh.command == RELAY_COMMAND_BEGIN_DIR &&
+          circ->purpose != CIRCUIT_PURPOSE_S_REND_JOINED) {
         /* Assign this circuit and its app-ward OR connection a unique ID,
          * so that we can measure download times. The local edge and dir
          * connection will be assigned the same ID when they are created