mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-09-28 17:11:11 -09:00
Merge remote-tracking branch 'origin/GP-6834-dragonmacher-xml-parser-update'
This commit is contained in:
@@ -62,6 +62,8 @@ class ThreadedXmlPullParserImpl extends AbstractXmlPullParser {
|
|||||||
* @param file the input XML file
|
* @param file the input XML file
|
||||||
* @param errHandler the XML error handler
|
* @param errHandler the XML error handler
|
||||||
* @param validate true if the parse should validate against the DTD
|
* @param validate true if the parse should validate against the DTD
|
||||||
|
* @param capacity the number of items that can be added to the queue before the parsing thread
|
||||||
|
* will block
|
||||||
* @throws SAXException if an XML parse error occurs
|
* @throws SAXException if an XML parse error occurs
|
||||||
* @throws IOException if an i/o error occurs
|
* @throws IOException if an i/o error occurs
|
||||||
*/
|
*/
|
||||||
@@ -76,6 +78,8 @@ class ThreadedXmlPullParserImpl extends AbstractXmlPullParser {
|
|||||||
* @param file the input XML file
|
* @param file the input XML file
|
||||||
* @param errHandler the XML error handler
|
* @param errHandler the XML error handler
|
||||||
* @param validate true if the parse should validate against the DTD
|
* @param validate true if the parse should validate against the DTD
|
||||||
|
* @param capacity the number of items that can be added to the queue before the parsing thread
|
||||||
|
* will block
|
||||||
* @throws SAXException if an XML parse error occurs
|
* @throws SAXException if an XML parse error occurs
|
||||||
* @throws IOException if an i/o error occurs
|
* @throws IOException if an i/o error occurs
|
||||||
*/
|
*/
|
||||||
@@ -96,14 +100,15 @@ class ThreadedXmlPullParserImpl extends AbstractXmlPullParser {
|
|||||||
* Note: Only use this method if you know that the XML in the given stream
|
* Note: Only use this method if you know that the XML in the given stream
|
||||||
* contains its own internal validation (an internal dtd specification). For
|
* contains its own internal validation (an internal dtd specification). For
|
||||||
* XML files that use an external dtd file you should call
|
* XML files that use an external dtd file you should call
|
||||||
* {@link #XmlParser(File, ErrorHandler, boolean)}.
|
* {@link #ThreadedXmlPullParserImpl(File, ErrorHandler, boolean, int)}.
|
||||||
*
|
*
|
||||||
* @param input the XML input stream
|
* @param input the XML input stream
|
||||||
* @param inputName the name of the input stream
|
* @param inputName the name of the input stream
|
||||||
* @param errHandler the XML error handler
|
* @param errHandler the XML error handler
|
||||||
* @param validate true if the parse should validate against the DTD
|
* @param validate true if the parse should validate against the DTD
|
||||||
|
* @param capacity the number of items that can be added to the queue before the parsing thread
|
||||||
|
* will block
|
||||||
* @throws SAXException if an XML parse error occurs
|
* @throws SAXException if an XML parse error occurs
|
||||||
* @throws IOException if an i/o error occurs
|
|
||||||
*/
|
*/
|
||||||
ThreadedXmlPullParserImpl(InputStream input, String inputName, ErrorHandler errHandler,
|
ThreadedXmlPullParserImpl(InputStream input, String inputName, ErrorHandler errHandler,
|
||||||
boolean validate, int capacity) throws SAXException {
|
boolean validate, int capacity) throws SAXException {
|
||||||
@@ -206,7 +211,6 @@ class ThreadedXmlPullParserImpl extends AbstractXmlPullParser {
|
|||||||
public void dispose() {
|
public void dispose() {
|
||||||
disposed = true;
|
disposed = true;
|
||||||
parsingTask.cancel(true);
|
parsingTask.cancel(true);
|
||||||
// Msg.debug(this, id + "Disposed");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private class ContentHandlerRunnable implements Runnable {
|
private class ContentHandlerRunnable implements Runnable {
|
||||||
@@ -223,15 +227,18 @@ class ThreadedXmlPullParserImpl extends AbstractXmlPullParser {
|
|||||||
|
|
||||||
try {
|
try {
|
||||||
SAXParserFactory saxParserFactory = XmlUtilities.createSecureSAXParserFactory(true);
|
SAXParserFactory saxParserFactory = XmlUtilities.createSecureSAXParserFactory(true);
|
||||||
|
saxParserFactory.setFeature(
|
||||||
|
"http://apache.org/xml/features/nonvalidating/load-external-dtd", false);
|
||||||
saxParserFactory.setFeature("http://xml.org/sax/features/namespaces", false);
|
saxParserFactory.setFeature("http://xml.org/sax/features/namespaces", false);
|
||||||
saxParserFactory.setFeature("http://xml.org/sax/features/validation", validate);
|
saxParserFactory.setFeature("http://xml.org/sax/features/validation", validate);
|
||||||
saxParser = saxParserFactory.newSAXParser();
|
saxParser = saxParserFactory.newSAXParser();
|
||||||
saxParser.getXMLReader().setEntityResolver((publicId, systemId) -> {
|
saxParser.getXMLReader().setEntityResolver((publicId, systemId) -> {
|
||||||
if (resolveDir == null) {
|
if (resolveDir == null) {
|
||||||
return null;
|
return new InputSource(new StringReader("")); // empty DTD
|
||||||
}
|
}
|
||||||
ResourceFile resolvedFile =
|
|
||||||
new ResourceFile(resolveDir, new File(systemId).getName());
|
String filename = new File(systemId).getName();
|
||||||
|
ResourceFile resolvedFile = new ResourceFile(resolveDir, filename);
|
||||||
InputSource inputSource = new InputSource();
|
InputSource inputSource = new InputSource();
|
||||||
inputSource.setPublicId(publicId);
|
inputSource.setPublicId(publicId);
|
||||||
inputSource.setSystemId(resolvedFile.toURI().toString());
|
inputSource.setSystemId(resolvedFile.toURI().toString());
|
||||||
|
|||||||
@@ -4,9 +4,9 @@
|
|||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
* You may obtain a copy of the License at
|
* You may obtain a copy of the License at
|
||||||
*
|
*
|
||||||
* http://www.apache.org/licenses/LICENSE-2.0
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||||||
*
|
*
|
||||||
* Unless required by applicable law or agreed to in writing, software
|
* Unless required by applicable law or agreed to in writing, software
|
||||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
@@ -15,13 +15,13 @@
|
|||||||
*/
|
*/
|
||||||
package ghidra.xml;
|
package ghidra.xml;
|
||||||
|
|
||||||
import generic.jar.ResourceFile;
|
|
||||||
|
|
||||||
import java.io.*;
|
import java.io.*;
|
||||||
|
|
||||||
import org.xml.sax.ErrorHandler;
|
import org.xml.sax.ErrorHandler;
|
||||||
import org.xml.sax.SAXException;
|
import org.xml.sax.SAXException;
|
||||||
|
|
||||||
|
import generic.jar.ResourceFile;
|
||||||
|
|
||||||
public class XmlPullParserFactory {
|
public class XmlPullParserFactory {
|
||||||
public static void setCreateTracingParsers(XmlTracer xmlTracer) {
|
public static void setCreateTracingParsers(XmlTracer xmlTracer) {
|
||||||
throw new UnsupportedOperationException(
|
throw new UnsupportedOperationException(
|
||||||
@@ -39,9 +39,11 @@ public class XmlPullParserFactory {
|
|||||||
* the XML error handler
|
* the XML error handler
|
||||||
* @param validate
|
* @param validate
|
||||||
* true if the parse should validate against the DTD
|
* true if the parse should validate against the DTD
|
||||||
|
* @return the parser
|
||||||
* @throws SAXException
|
* @throws SAXException
|
||||||
* if an XML parse error occurs
|
* if an XML parse error occurs
|
||||||
* @throws IOException
|
* @throws IOException
|
||||||
|
* if an i/o error occurs
|
||||||
*/
|
*/
|
||||||
public static XmlPullParser create(InputStream input, String inputName,
|
public static XmlPullParser create(InputStream input, String inputName,
|
||||||
ErrorHandler errHandler, boolean validate) throws SAXException, IOException {
|
ErrorHandler errHandler, boolean validate) throws SAXException, IOException {
|
||||||
@@ -57,6 +59,7 @@ public class XmlPullParserFactory {
|
|||||||
* the XML error handler
|
* the XML error handler
|
||||||
* @param validate
|
* @param validate
|
||||||
* true if the parse should validate against the DTD
|
* true if the parse should validate against the DTD
|
||||||
|
* @return the parser
|
||||||
* @throws SAXException
|
* @throws SAXException
|
||||||
* if an XML parse error occurs
|
* if an XML parse error occurs
|
||||||
* @throws IOException
|
* @throws IOException
|
||||||
@@ -76,6 +79,7 @@ public class XmlPullParserFactory {
|
|||||||
* the XML error handler
|
* the XML error handler
|
||||||
* @param validate
|
* @param validate
|
||||||
* true if the parse should validate against the DTD
|
* true if the parse should validate against the DTD
|
||||||
|
* @return the parser
|
||||||
* @throws SAXException
|
* @throws SAXException
|
||||||
* if an XML parse error occurs
|
* if an XML parse error occurs
|
||||||
* @throws IOException
|
* @throws IOException
|
||||||
@@ -97,6 +101,7 @@ public class XmlPullParserFactory {
|
|||||||
* the XML error handler
|
* the XML error handler
|
||||||
* @param validate
|
* @param validate
|
||||||
* true if the parse should validate against the DTD
|
* true if the parse should validate against the DTD
|
||||||
|
* @return the parser
|
||||||
* @throws SAXException
|
* @throws SAXException
|
||||||
* if an XML parse error occurs
|
* if an XML parse error occurs
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -4,9 +4,9 @@
|
|||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
* You may obtain a copy of the License at
|
* You may obtain a copy of the License at
|
||||||
*
|
*
|
||||||
* http://www.apache.org/licenses/LICENSE-2.0
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||||||
*
|
*
|
||||||
* Unless required by applicable law or agreed to in writing, software
|
* Unless required by applicable law or agreed to in writing, software
|
||||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
@@ -44,17 +44,11 @@ public class ThreadedXmlParserTest extends AbstractGenericTest {
|
|||||||
"<project name=\"foo\"/>" + "<project name=\"foo\"/>" + "<project name=\"foo\"/>" +
|
"<project name=\"foo\"/>" + "<project name=\"foo\"/>" + "<project name=\"foo\"/>" +
|
||||||
"<project name=\"foo\"/>" + "</doc>";
|
"<project name=\"foo\"/>" + "</doc>";
|
||||||
|
|
||||||
|
|
||||||
private static final String XXE_XML = "<?xml version=\"1.0\" encoding=\"ISO-8859-1\"?>\n" +
|
private static final String XXE_XML = "<?xml version=\"1.0\" encoding=\"ISO-8859-1\"?>\n" +
|
||||||
"<!DOCTYPE foo [\n" + " <!ELEMENT foo ANY >\n" +
|
"<!DOCTYPE foo [\n" + " <!ELEMENT foo ANY >\n" +
|
||||||
"<!ENTITY xxe SYSTEM \"file://@TEMP_FILE@\">]><foo>&xxe; fizzbizz</foo>";
|
"<!ENTITY xxe SYSTEM \"file://@TEMP_FILE@\">]><foo>&xxe; fizzbizz</foo>";
|
||||||
|
|
||||||
public ThreadedXmlParserTest() {
|
|
||||||
super();
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* <p>
|
|
||||||
* XML External Entities attacks benefit from an XML feature to build documents dynamically at
|
* XML External Entities attacks benefit from an XML feature to build documents dynamically at
|
||||||
* the time of processing. An XML entity allows inclusion of data dynamically from a given
|
* the time of processing. An XML entity allows inclusion of data dynamically from a given
|
||||||
* resource. External entities allow an XML document to include data from an external URI.
|
* resource. External entities allow an XML document to include data from an external URI.
|
||||||
@@ -71,7 +65,7 @@ public class ThreadedXmlParserTest extends AbstractGenericTest {
|
|||||||
* than ResourceFile) will use a default Entity Resolver. The XmlUtilities.createSecureSAXParserFactory
|
* than ResourceFile) will use a default Entity Resolver. The XmlUtilities.createSecureSAXParserFactory
|
||||||
* factory configurations will disable external entities regardless of which Entity Resolver is used.
|
* factory configurations will disable external entities regardless of which Entity Resolver is used.
|
||||||
*
|
*
|
||||||
* @throws Exception
|
* @throws Exception if there is an exception
|
||||||
*/
|
*/
|
||||||
@Test
|
@Test
|
||||||
public void testXXEXml() throws Exception {
|
public void testXXEXml() throws Exception {
|
||||||
|
|||||||
Reference in New Issue
Block a user