mirror of
https://github.com/nginx/nginx.git
synced 2025-02-25 18:55:26 -06:00
Fixed incorrect ngx_cpystrn() usage in ngx_http_*_process_header().
This resulted in a disclosure of previously freed memory if upstream server returned specially crafted response, potentially exposing sensitive information. Reported by Matthew Daley.
This commit is contained in:
parent
030e235ec7
commit
eb526b7d7d
@ -1501,10 +1501,10 @@ ngx_http_fastcgi_process_header(ngx_http_request_t *r)
|
||||
h->lowcase_key = h->key.data + h->key.len + 1
|
||||
+ h->value.len + 1;
|
||||
|
||||
ngx_cpystrn(h->key.data, r->header_name_start,
|
||||
h->key.len + 1);
|
||||
ngx_cpystrn(h->value.data, r->header_start,
|
||||
h->value.len + 1);
|
||||
ngx_memcpy(h->key.data, r->header_name_start, h->key.len);
|
||||
h->key.data[h->key.len] = '\0';
|
||||
ngx_memcpy(h->value.data, r->header_start, h->value.len);
|
||||
h->value.data[h->value.len] = '\0';
|
||||
}
|
||||
|
||||
h->hash = r->header_hash;
|
||||
|
@ -1381,8 +1381,10 @@ ngx_http_proxy_process_header(ngx_http_request_t *r)
|
||||
h->value.data = h->key.data + h->key.len + 1;
|
||||
h->lowcase_key = h->key.data + h->key.len + 1 + h->value.len + 1;
|
||||
|
||||
ngx_cpystrn(h->key.data, r->header_name_start, h->key.len + 1);
|
||||
ngx_cpystrn(h->value.data, r->header_start, h->value.len + 1);
|
||||
ngx_memcpy(h->key.data, r->header_name_start, h->key.len);
|
||||
h->key.data[h->key.len] = '\0';
|
||||
ngx_memcpy(h->value.data, r->header_start, h->value.len);
|
||||
h->value.data[h->value.len] = '\0';
|
||||
|
||||
if (h->key.len == r->lowcase_index) {
|
||||
ngx_memcpy(h->lowcase_key, r->lowcase_header, h->key.len);
|
||||
|
@ -941,8 +941,10 @@ ngx_http_scgi_process_header(ngx_http_request_t *r)
|
||||
h->value.data = h->key.data + h->key.len + 1;
|
||||
h->lowcase_key = h->key.data + h->key.len + 1 + h->value.len + 1;
|
||||
|
||||
ngx_cpystrn(h->key.data, r->header_name_start, h->key.len + 1);
|
||||
ngx_cpystrn(h->value.data, r->header_start, h->value.len + 1);
|
||||
ngx_memcpy(h->key.data, r->header_name_start, h->key.len);
|
||||
h->key.data[h->key.len] = '\0';
|
||||
ngx_memcpy(h->value.data, r->header_start, h->value.len);
|
||||
h->value.data[h->value.len] = '\0';
|
||||
|
||||
if (h->key.len == r->lowcase_index) {
|
||||
ngx_memcpy(h->lowcase_key, r->lowcase_header, h->key.len);
|
||||
|
@ -981,8 +981,10 @@ ngx_http_uwsgi_process_header(ngx_http_request_t *r)
|
||||
h->value.data = h->key.data + h->key.len + 1;
|
||||
h->lowcase_key = h->key.data + h->key.len + 1 + h->value.len + 1;
|
||||
|
||||
ngx_cpystrn(h->key.data, r->header_name_start, h->key.len + 1);
|
||||
ngx_cpystrn(h->value.data, r->header_start, h->value.len + 1);
|
||||
ngx_memcpy(h->key.data, r->header_name_start, h->key.len);
|
||||
h->key.data[h->key.len] = '\0';
|
||||
ngx_memcpy(h->value.data, r->header_start, h->value.len);
|
||||
h->value.data[h->value.len] = '\0';
|
||||
|
||||
if (h->key.len == r->lowcase_index) {
|
||||
ngx_memcpy(h->lowcase_key, r->lowcase_header, h->key.len);
|
||||
|
Loading…
Reference in New Issue
Block a user