Address issues identified by external review:

* RIPD-1617, RIPD-1619, RIPD-1621:
  Verify serialized public keys more strictly before
  using them.

* RIPD-1618:
    * Simplify the base58 decoder logic.
    * Reduce the complexity of the base58 encoder and
      eliminate a potential out-of-bounds memory access.
    * Improve type safety by using an `enum class` to
      enforce strict type checking for token types.

* RIPD-1616:
  Avoid calling `memcpy` with a null pointer even if the
  size is specified as zero, since it results in undefined
  behavior.

Acknowledgements:
Ripple thanks Guido Vranken for responsibly disclosing these
issues.

Bug Bounties and Responsible Disclosures:
We welcome reviews of the rippled code and urge researchers
to responsibly disclose any issues that they may find. For
more on Ripple's Bug Bounty program, please visit:
https://ripple.com/bug-bounty
This commit is contained in:
Nikolaos D. Bougalis
2018-03-15 20:58:05 -07:00
parent 25de6b0a5f
commit d5f981f5fc
47 changed files with 393 additions and 264 deletions

View File

@@ -69,7 +69,7 @@ class AccountCurrencies_test : public beast::unit_test::suite
{ // strict mode, using properly formatted bitcoin token
Json::Value params;
params[jss::account] = base58EncodeTokenBitcoin (
TOKEN_ACCOUNT_ID, alice.id().data(), alice.id().size());
TokenType::AccountID, alice.id().data(), alice.id().size());
params[jss::strict] = true;
auto const result = env.rpc ("json", "account_currencies",
boost::lexical_cast<std::string>(params)) [jss::result];