From cdb45cc05f65a378172de7e6a472cbff35149a92 Mon Sep 17 00:00:00 2001 From: seonghobae <8172694+seonghobae@users.noreply.github.com> Date: Mon, 28 Sep 2026 19:21:18 +0000 Subject: [PATCH 1/2] =?UTF-8?q?=EB=8C=80=ED=99=94=ED=98=95=20=ED=94=84?= =?UTF-8?q?=EB=A1=AC=ED=94=84=ED=8A=B8=EC=9D=98=20=EC=A0=95=EC=88=98=20?= =?UTF-8?q?=EC=98=A4=EB=B2=84=ED=94=8C=EB=A1=9C=EC=9A=B0=20DoS=20=EC=B7=A8?= =?UTF-8?q?=EC=95=BD=EC=A0=90=20=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit R의 readline() 함수를 통한 입력 검증 시 사용된 정규표현식(`grepl("^[0-9]+$", n)`)을 정확한 문자열 매칭(`n %in% c("1", "2")`)으로 대체하여, 매우 큰 숫자가 입력될 경우 발생하는 as.integer()의 정수 오버플로우 DoS 취약점을 수정했습니다. --- .jules/sentinel.md | 8 ++++---- R/aFIPC.R | 6 +++--- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/.jules/sentinel.md b/.jules/sentinel.md index a8207a48..826911e0 100644 --- a/.jules/sentinel.md +++ b/.jules/sentinel.md @@ -1,4 +1,4 @@ -## 2024-07-12 - Fix missing parameter validations -**Vulnerability:** Unvalidated inputs passed to `if()` statements can cause process crashes (`condition has length > 1`) or unexpected coercion vulnerabilities. -**Learning:** In R, optional boolean parameters that default to `NULL` should be validated using explicit runtime type validation (e.g., `if (!is.null(flag) && (!is.logical(flag) || length(flag) != 1 || is.na(flag)))`). -**Prevention:** Always implement explicit runtime type validation for optional boolean parameters. +## 2024-09-28 - Integer Overflow DoS in R's readline() validation +**Vulnerability:** A DoS risk was present where interactive numeric prompts (`readline()`) were validated against the regex `grepl("^[0-9]+$", n)`. When a very large numeric string is passed, it passes the regex but causes an integer overflow when coerced with `as.integer()`, resulting in `NA`. Evaluating `NA` in logical checks later on would crash the application. +**Learning:** R handles large numeric string coercion to integer differently from what basic numeric regex checks account for, making regex alone an insecure validation method for strictly predefined input choices. +**Prevention:** For strictly predefined input options (like "1" and "2"), always validate input using exact string matching (`n %in% c("1", "2")`) instead of relying on broad numeric regex checks. diff --git a/R/aFIPC.R b/R/aFIPC.R index 62546519..118aca09 100644 --- a/R/aFIPC.R +++ b/R/aFIPC.R @@ -141,7 +141,7 @@ autoFIPC <- } for (attempt in seq_len(3)) { n <- readline(prompt = "Is it correct? (1: Yes 2: No) : ") - if (grepl("^[0-9]+$", n)) { + if (n %in% c("1", "2")) { return(as.integer(n)) } } @@ -171,7 +171,7 @@ autoFIPC <- readline( prompt = "Do you want to use default BILOG-MG priors for oldform Data? (1: Yes 2: No) : " ) - if (grepl("^[0-9]+$", n)) { + if (n %in% c("1", "2")) { return(as.integer(n)) } } @@ -390,7 +390,7 @@ autoFIPC <- readline( prompt = "Do you want to use default BILOG-MG priors for newform Data? (1: Yes 2: No) : " ) - if (grepl("^[0-9]+$", n)) { + if (n %in% c("1", "2")) { return(as.integer(n)) } } From 0ca9911ef48e2fbc5e5c51a296ce5f83234cc041 Mon Sep 17 00:00:00 2001 From: seonghobae <8172694+seonghobae@users.noreply.github.com> Date: Wed, 30 Sep 2026 05:31:06 +0000 Subject: [PATCH 2/2] =?UTF-8?q?PR=20=ED=96=89=EC=A0=95=20=EC=83=81?= =?UTF-8?q?=ED=83=9C=20=EC=A0=84=ED=99=98=20=ED=99=95=EC=9D=B8=20=EB=B0=8F?= =?UTF-8?q?=20=EC=9D=91=EB=8B=B5=20=EB=B0=98=EC=98=81?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit PR이 초안(Draft) 상태로 전환되었음을 인지하고 관리 시스템의 지침을 확인하기 위한 응답을 남겼습니다. 코드 수정 사항은 없습니다.