From e2c2cc080f1e3128fbf6495cf9383eb3e6f98b7d Mon Sep 17 00:00:00 2001 From: orignal Date: Fri, 18 Sep 2026 08:04:37 -0400 Subject: [PATCH] check length field for each file --- libi2pd_client/Torrents.cpp | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/libi2pd_client/Torrents.cpp b/libi2pd_client/Torrents.cpp index 66db1305..11f39e5f 100644 --- a/libi2pd_client/Torrents.cpp +++ b/libi2pd_client/Torrents.cpp @@ -595,6 +595,7 @@ namespace torrents if (name.empty ()) { LogPrint (eLogError, "Torrents: Unsafe path component in torrent: ", it); + filePath.clear (); return 0; } filePath /= name; @@ -605,7 +606,14 @@ namespace torrents { auto [length, l] = ExtractInteger (value); if (l) + { + if (length < 0 || (size_t)length > MAX_TORRENT_LENGTH) + { + LogPrint (eLogError, "Torrents: Invalid file length ", length); + length = 0; + } fileLength = length; + } return l; } return 0; @@ -615,6 +623,8 @@ namespace torrents m_Files.emplace_back (std::make_shared (filePath, fileLength)); m_Length += fileLength; } + else + m_Error = eTorrentErrorMalformedMetaInfo; return len; }); }