Hello,
Follow-up scan after looking at v2.9 — the same CVE-2024-10964 fix is also missing on the older v2.8 branch.
Upstream fix: 3e3a583d — plugin:buffer overflow (replaces strcpy() with strncpy(..., NEU_PLUGIN_LIBRARY_LEN)).
State on v2.8 (HEAD 6c58bfe2128a):
| function |
line on v2.8 |
handle_add_plugin |
strcpy(cmd.library, req->library); |
handle_update_plugin |
strcpy(cmd.library, req->library); |
Both still call the unbounded strcpy() against attacker-controllable req->library, so the original buffer-overflow condition is reachable.
compare v2.8...main reports diverged, ahead=698, behind=148, so the branch is actively maintained.
The minimum diff is identical to the upstream +2/-2 change in plugins/restful/plugin_handle.c; the master-only otel_trace_type field is not on v2.8 and is not needed.
Happy to send the cherry-pick as a PR if that helps. Thanks for maintaining v2.x!
Hello,
Follow-up scan after looking at
v2.9— the same CVE-2024-10964 fix is also missing on the olderv2.8branch.Upstream fix:
3e3a583d—plugin:buffer overflow(replacesstrcpy()withstrncpy(..., NEU_PLUGIN_LIBRARY_LEN)).State on
v2.8(HEAD6c58bfe2128a):handle_add_pluginstrcpy(cmd.library, req->library);handle_update_pluginstrcpy(cmd.library, req->library);Both still call the unbounded
strcpy()against attacker-controllablereq->library, so the original buffer-overflow condition is reachable.compare v2.8...mainreportsdiverged, ahead=698, behind=148, so the branch is actively maintained.The minimum diff is identical to the upstream
+2/-2change inplugins/restful/plugin_handle.c; the master-onlyotel_trace_typefield is not onv2.8and is not needed.Happy to send the cherry-pick as a PR if that helps. Thanks for maintaining
v2.x!