mirror of
https://github.com/irssi/irssi.git
synced 2026-08-20 17:12:51 +02:00
Merge 283d846787 into 43f1727ef9
This commit is contained in:
commit
8c46b61e43
1 changed files with 10 additions and 0 deletions
|
|
@ -730,6 +730,16 @@ static void dcc_chat_msg(CHAT_DCC_REC *dcc, const char *msg)
|
||||||
if (*msg != 1)
|
if (*msg != 1)
|
||||||
return;
|
return;
|
||||||
|
|
||||||
|
/* Cap the CTCP body length that is concatenated into the signal name. The
|
||||||
|
* body comes from a remote peer on an established DCC CHAT connection
|
||||||
|
* and is passed as the second argument to any matching signal handler
|
||||||
|
* (including loaded perl scripts). A modest cap limits the attack surface
|
||||||
|
* for the dynamic-signal-name dispatch and aligns with the convention
|
||||||
|
* used for CTCP-over-IRC. */
|
||||||
|
if (strlen(msg+1) > 256) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
/* get ctcp command, remove \001 chars */
|
/* get ctcp command, remove \001 chars */
|
||||||
event = g_strconcat(reply ? "dcc reply " : "dcc ctcp ", msg+1, NULL);
|
event = g_strconcat(reply ? "dcc reply " : "dcc ctcp ", msg+1, NULL);
|
||||||
if (event[strlen(event)-1] == 1) event[strlen(event)-1] = '\0';
|
if (event[strlen(event)-1] == 1) event[strlen(event)-1] = '\0';
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue