Executive brief
rdiffweb is a web-based backup client and server used to manage incremental file backups. Due to a lack of length validation on token names, an attacker can submit an extremely long token name that causes the application to allocate excessive memory, resulting in denial of service or memory corruption that crashes the service.
Technical details
rdiffweb prior to version 2.5.0a3 contains an Allocation of Resources Without Limits or Throttling vulnerability (CWE-770) in its token name parameter. The application fails to enforce a maximum length limit on the token name field, allowing an attacker to send a request with an excessively long token name. This causes uncontrolled memory allocation, leading to denial of service or potential memory corruption. The vulnerability requires network access but no authentication, allowing unauthenticated remote attackers to trigger the issue. The fix limits the length of token name and fullname fields, mitigating resource exhaustion.
Affected products
- rdiffweb rdiffweb before 2.5.0a3
Timeline
- 2022-10-01: disclosed
- 2022-10-01: patched: Version 2.5.0a3 fixes the issue