BUG #19702: decode() accepts Base64 payload after terminal padding - Mailing list pgsql-bugs

From PG Bug reporting form
Subject BUG #19702: decode() accepts Base64 payload after terminal padding
Date
Msg-id 19702-9ed4a131fcfadb9d@postgresql.org
Whole thread
Responses Re: BUG #19702: decode() accepts Base64 payload after terminal padding
List pgsql-bugs
The following bug has been logged on the website:

Bug reference:      19702
Logged by:          Qifan Liu
Email address:      imchifan@163.com
PostgreSQL version: 18.6
Operating system:   Linux/amd64
Description:

decode() accepts Base64 alphabet characters after terminal '=' padding and
incorporates them into the decoded bytea value. Once terminal padding
completes a Base64 value, only ignorable whitespace may follow. Applications
relying on decode() to validate Base64 input may consequently process
malformed input as valid data.

Steps to reproduce
------------------
Run the following with psql:

\set ON_ERROR_STOP on
SELECT encode(decode('YQ==Yg==', 'base64'), 'hex') AS decoded_hex;
SELECT encode(decode('YQ==AAAA', 'base64'), 'hex') AS
decoded_hex_after_padding;

Actual result
-------------
 decoded_hex
-------------
 6162
(1 row)

 decoded_hex_after_padding
---------------------------
 6100
(1 row)

Expected result
---------------
Both decode() calls should reject their input with SQLSTATE 22023 because
Base64 alphabet characters occur after terminal '=' padding. They should not
silently decode the trailing payload.

Additional information
----------------------
The issue was reproduced on PostgreSQL 20devel, PostgreSQL 18.6, and
PostgreSQL 17.11.





pgsql-bugs by date:

Previous
From: Michael Paquier
Date:
Subject: Re: BUG #19693: JSON_VALUE/JSON_QUERY PASSING a toasted text value reads the toast pointer instead of the text
Next
From: PG Bug reporting form
Date:
Subject: BUG #19703: information_schema.usage_privileges omits a sequence owner's implicit USAGE privilege