Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stop processing messages larger than max size #110

Open
fehlmach opened this issue Nov 6, 2018 · 0 comments
Open

Stop processing messages larger than max size #110

fehlmach opened this issue Nov 6, 2018 · 0 comments

Comments

@fehlmach
Copy link
Contributor

fehlmach commented Nov 6, 2018

The cbor library should keep track of how many bytes it has already processed of a given message and if it is larger than the maximum message size, abort parsing and return an error.
Otherwise denial of service is trivial against a RAINS server/client

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant