Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Avoid potential DoS with high decompression chunks #157

Merged

Conversation

sarroutbi
Copy link
Collaborator

No description provided.

@sarroutbi sarroutbi force-pushed the 202409051719-jwe-compression-limit branch from d97b3bc to 7b769d8 Compare May 9, 2024 15:23
lib/jwe.c Outdated Show resolved Hide resolved
tests/api_jwe.c Outdated Show resolved Hide resolved
@sarroutbi sarroutbi force-pushed the 202409051719-jwe-compression-limit branch from 7b769d8 to 6655ee7 Compare May 14, 2024 16:55
@sarroutbi sarroutbi marked this pull request as draft May 14, 2024 16:55
@sarroutbi sarroutbi removed the request for review from sergio-correia May 14, 2024 16:55
@sarroutbi sarroutbi force-pushed the 202409051719-jwe-compression-limit branch 4 times, most recently from bb50ede to beb41df Compare May 14, 2024 17:14
@sarroutbi sarroutbi marked this pull request as ready for review May 14, 2024 17:19
Copy link
Member

@simo5 simo5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mines are mostly nits, feel free to ignore

lib/hooks.h Outdated Show resolved Hide resolved
lib/zlib/deflate.c Outdated Show resolved Hide resolved
tests/alg_comp.c Outdated Show resolved Hide resolved
@sarroutbi sarroutbi force-pushed the 202409051719-jwe-compression-limit branch 2 times, most recently from 284d390 to 7110901 Compare May 16, 2024 08:45
@sarroutbi sarroutbi changed the title Avoid potential DoS with high compression Avoid potential DoS with high decompression chunks May 16, 2024
@sarroutbi sarroutbi force-pushed the 202409051719-jwe-compression-limit branch from 7110901 to 95c1565 Compare May 16, 2024 08:46
@sarroutbi sarroutbi requested a review from simo5 May 16, 2024 09:10
Copy link
Member

@simo5 simo5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@sarroutbi
Copy link
Collaborator Author

LGTM!

Thanks for your support @simo5

Copy link
Collaborator

@sergio-correia sergio-correia left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, LGTM

@sarroutbi sarroutbi merged commit efb5cfa into latchset:master May 17, 2024
22 checks passed
@sarroutbi sarroutbi deleted the 202409051719-jwe-compression-limit branch May 17, 2024 08:54
@sarroutbi sarroutbi mentioned this pull request May 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants