Created on 2020-07-17.23:53:59 by admin, last changed by admin.
| Messages | |||
|---|---|---|---|
| msg902 (view) | Author: admin | Date: 2020-07-17.23:53:59 | |
[Bugzilla user: smn@nebelhauch.de] [Bugzilla date: 2020-07-17T21:53:59+00:00] Hallo, Orthanc, namely libpython according to the trace, segfaults if a REST callback handler registered within the python plugin receives non-UTF8-encoded request parameters. This concerns for example ISO-8859-1 encoded German Umlauts (Ä, Ö, Ü, ...) in GET-query parameters (ex.: http://orthanc-host/worklist/add?lastname=Müller&firstname=Cäcilia). The segfault occurs before the request callback handler is invoked (a log message placed as first instruction in callback handler is not printed before the segfault occurs). Encoding to UTF-8 solves the problem. From my point of view it's a security or stability issue nonetheless, as everyone who may call the REST API can pass any bytes she wants as Query parameters paying no attention to the correct encoding and a segfault effectively termiantes the complete Orthanc service at the moment as there doesn't seem to be any sandboxing. |
|||
| msg903 (view) | Author: admin | Date: 2020-08-02.12:13:39 | |
[Bugzilla user: s.jodogne@gmail.com] [Bugzilla date: 2020-08-02T10:13:39+00:00] Hello, Thanks for your report, but I'm unable to reproduce the issue on my Ubuntu 18.04 box. Please provide a full minimal working example (Python sample + curl command-line) so that we can work on a fix: https://book.orthanc-server.com/users/support.html#discussing-a-minimal-working-example Kind Regards, Sébastien- |
|||
| msg904 (view) | Author: admin | Date: 2020-08-03.15:14:44 | |
[Bugzilla user: smn@nebelhauch.de] [Bugzilla date: 2020-08-03T13:14:44+00:00] Python script below: # segfault example import orthanc def OnRest(output, uri, **request): orthanc.LogWarning("REST call on {uri}".format(uri = uri)) output.AnswerBuffer('Ok\n', 'text/plain') orthanc.RegisterRestCallback('/worklist/add', OnRest) # end example curl (invoked on Windows from cmd.exe): > curl http://192.168.100.10:8091/worklist/add?name=Schr%F6der Result: Orthanc segfaults before the LogWarning line is reached. The corresponding dmesg entry for the segfault is: [34308133.217406] Orthanc[17277]: segfault at 0 ip 00007f9bfa810bac sp 00007f9bd8ff3ae0 error 6 in libpython3.7m.so.1.0[7f9bfa63c000+22c000] If it helps to reproduce: I'm running Orthanc in a docker container via an image derived from the official orthanc-plugins docker image. If required I can also supply the Dockerfile used. |
|||
| msg905 (view) | Author: admin | Date: 2020-08-03.18:14:59 | |
[Bugzilla user: s.jodogne@gmail.com] [Bugzilla date: 2020-08-03T16:14:59+00:00] Thanks for your instructions! This issue is now fixed in the mainline of the plugin, and will be part of the next release: https://hg.orthanc-server.com/orthanc-python/rev/ee76cced46a5 |
|||
| History | |||
|---|---|---|---|
| Date | User | Action | Args |
| 2026-07-29 15:51:27 | admin | create | |