mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-11-10 13:13:44 +01:00
Merge branch 'ticket40730_045_01' into maint-0.4.5
This commit is contained in:
commit
7b83e336ec
5
changes/ticket40730
Normal file
5
changes/ticket40730
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
o Major bugfixes (TROVE-2022-002, client):
|
||||||
|
- The SafeSocks option had its logic inverted for SOCKS4 and SOCKS4a. It
|
||||||
|
would let the unsafe SOCKS4 pass but not the safe SOCKS4a one. This is
|
||||||
|
TROVE-2022-002 which was reported on Hackerone by "cojabo". Fixes bug
|
||||||
|
40730; bugfix on 0.3.5.1-alpha.
|
@ -233,7 +233,7 @@ static socks_result_t
|
|||||||
process_socks4_request(const socks_request_t *req, int is_socks4a,
|
process_socks4_request(const socks_request_t *req, int is_socks4a,
|
||||||
int log_sockstype, int safe_socks)
|
int log_sockstype, int safe_socks)
|
||||||
{
|
{
|
||||||
if (is_socks4a && !addressmap_have_mapping(req->address, 0)) {
|
if (!is_socks4a && !addressmap_have_mapping(req->address, 0)) {
|
||||||
log_unsafe_socks_warning(4, req->address, req->port, safe_socks);
|
log_unsafe_socks_warning(4, req->address, req->port, safe_socks);
|
||||||
|
|
||||||
if (safe_socks)
|
if (safe_socks)
|
||||||
|
Loading…
Reference in New Issue
Block a user