mirror of
https://github.com/nlohmann/json.git
synced 2026-09-17 13:47:58 +00:00
fix: check CBOR tagged subtype reads (#5339)
This commit is contained in:
@@ -811,25 +811,37 @@ class binary_reader
|
|||||||
case 0xD8:
|
case 0xD8:
|
||||||
{
|
{
|
||||||
std::uint8_t subtype_to_ignore{};
|
std::uint8_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xD9:
|
case 0xD9:
|
||||||
{
|
{
|
||||||
std::uint16_t subtype_to_ignore{};
|
std::uint16_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDA:
|
case 0xDA:
|
||||||
{
|
{
|
||||||
std::uint32_t subtype_to_ignore{};
|
std::uint32_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDB:
|
case 0xDB:
|
||||||
{
|
{
|
||||||
std::uint64_t subtype_to_ignore{};
|
std::uint64_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
default:
|
default:
|
||||||
@@ -847,28 +859,40 @@ class binary_reader
|
|||||||
case 0xD8:
|
case 0xD8:
|
||||||
{
|
{
|
||||||
std::uint8_t subtype{};
|
std::uint8_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xD9:
|
case 0xD9:
|
||||||
{
|
{
|
||||||
std::uint16_t subtype{};
|
std::uint16_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDA:
|
case 0xDA:
|
||||||
{
|
{
|
||||||
std::uint32_t subtype{};
|
std::uint32_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDB:
|
case 0xDB:
|
||||||
{
|
{
|
||||||
std::uint64_t subtype{};
|
std::uint64_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11360,25 +11360,37 @@ class binary_reader
|
|||||||
case 0xD8:
|
case 0xD8:
|
||||||
{
|
{
|
||||||
std::uint8_t subtype_to_ignore{};
|
std::uint8_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xD9:
|
case 0xD9:
|
||||||
{
|
{
|
||||||
std::uint16_t subtype_to_ignore{};
|
std::uint16_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDA:
|
case 0xDA:
|
||||||
{
|
{
|
||||||
std::uint32_t subtype_to_ignore{};
|
std::uint32_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDB:
|
case 0xDB:
|
||||||
{
|
{
|
||||||
std::uint64_t subtype_to_ignore{};
|
std::uint64_t subtype_to_ignore{};
|
||||||
get_number(input_format_t::cbor, subtype_to_ignore);
|
if (!get_number(input_format_t::cbor, subtype_to_ignore))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
default:
|
default:
|
||||||
@@ -11396,28 +11408,40 @@ class binary_reader
|
|||||||
case 0xD8:
|
case 0xD8:
|
||||||
{
|
{
|
||||||
std::uint8_t subtype{};
|
std::uint8_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xD9:
|
case 0xD9:
|
||||||
{
|
{
|
||||||
std::uint16_t subtype{};
|
std::uint16_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDA:
|
case 0xDA:
|
||||||
{
|
{
|
||||||
std::uint32_t subtype{};
|
std::uint32_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case 0xDB:
|
case 0xDB:
|
||||||
{
|
{
|
||||||
std::uint64_t subtype{};
|
std::uint64_t subtype{};
|
||||||
get_number(input_format_t::cbor, subtype);
|
if (!get_number(input_format_t::cbor, subtype))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
b.set_subtype(detail::conditional_static_cast<typename binary_t::subtype_type>(subtype));
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1530,4 +1530,29 @@ TEST_CASE("issue #4320 - custom base class must not leak nlohmann::detail into A
|
|||||||
CHECK(j == json({{"x", 1.0}, {"y", 2.0}, {"z", 3.0}}));
|
CHECK(j == json({{"x", 1.0}, {"y", 2.0}, {"z", 3.0}}));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
TEST_CASE("issue #5338 - truncated CBOR tagged binary subtype is rejected")
|
||||||
|
{
|
||||||
|
const std::vector<std::vector<std::uint8_t>> truncated_tags =
|
||||||
|
{
|
||||||
|
{0xD8},
|
||||||
|
{0xD9, 0x00},
|
||||||
|
{0xDA, 0x00, 0x00, 0x00},
|
||||||
|
{0xDB, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}
|
||||||
|
};
|
||||||
|
|
||||||
|
for (const auto& data : truncated_tags)
|
||||||
|
{
|
||||||
|
CAPTURE(data);
|
||||||
|
for (const auto tag_handler :
|
||||||
|
{
|
||||||
|
json::cbor_tag_handler_t::ignore, json::cbor_tag_handler_t::store
|
||||||
|
})
|
||||||
|
{
|
||||||
|
CAPTURE(tag_handler);
|
||||||
|
const auto result = json::from_cbor(data, true, false, tag_handler);
|
||||||
|
CHECK(result.is_discarded());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
DOCTEST_CLANG_SUPPRESS_WARNING_POP
|
DOCTEST_CLANG_SUPPRESS_WARNING_POP
|
||||||
|
|||||||
Reference in New Issue
Block a user