directory-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Emmanuel Lecharny (JIRA)" <>
Subject [jira] Reopened: (DIRSERVER-1196) Filter with special characters crashes JVM
Date Thu, 10 Jul 2008 10:12:31 GMT


Emmanuel Lecharny reopened DIRSERVER-1196:

There is a big bug in the way filters are handled into the server. If a filter contains ecaped
chars, like :
(description=this is a filter with escaped parentheses : \28\29)

then the entry is never found. 

This is because the filter escaped chars are never unescaped.

I have a fix for this, I will apply it after lunch.

> Filter with special characters crashes JVM
> ------------------------------------------
>                 Key: DIRSERVER-1196
>                 URL:
>             Project: Directory ApacheDS
>          Issue Type: Bug
>          Components: core
>    Affects Versions: 1.5.3
>         Environment: Windows running under jboss
>            Reporter: Steve hammond
>            Assignee: Emmanuel Lecharny
>             Fix For: 1.5.3
> the following command 
>          FilterParser.parse("(memberOf=1.2.840.113556.1.4.1301=$#@&*()==,,,");
> will put the filter parser apparently into an infinite loop until the JVM crashes.
> aparently it is the () in the middle.  LDAPStudio does not allow that in the filter,
neither does ldapsearch.
> So maybe just a check for parenthesis somewhere in the parse and a throw?  Are those
the only 2 characters that a value cannot have?

This message is automatically generated by JIRA.
You can reply to this email to add a comment to the issue online.

View raw message