Uploaded image for project: 'MariaDB Connector/C'
  1. MariaDB Connector/C
  2. CONC-840

Add max_allowed_columns option to bound server-announced column count

    XMLWordPrintable

Details

    • Task
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • 3.3.19, 3.4.9
    • 3.3.20, 3.4.10
    • Internal
    • None

    Description

      When reading result-set or prepare metadata, the driver allocates a ColumnDecoder array sized to the column count announced by the server (a length-encoded integer, up to Integer.MAX_VALUE). A malicious man-in-the-middle proxy can announce an enormous column count to force a huge allocation and exhaust client memory (OOM), before any actual column packets are read.

      Add a new connection option maxAllowedColumns (default 65535) that rejects the command with an SQLException when the announced column count exceeds the limit, before allocating. 65535 matches the wire-format cap already imposed on prepare-statement column/param counts.

      MariadDB/MySQL tables columns limit is 4k (1017 for InnoDB), so 64K limit is ok.

      thanks fg0x0 for report

      Attachments

        Issue Links

          Activity

            People

              georg Georg Richter
              diego dupin Diego Dupin
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Git Integration

                  Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.