]> git.kaiwu.me - nginx.git/commitdiff
Detect runaway chunks in ngx_http_parse_chunked().
authorSergey Kandaurov <pluknet@nginx.com>
Tue, 3 Sep 2019 14:26:56 +0000 (17:26 +0300)
committerSergey Kandaurov <pluknet@nginx.com>
Tue, 3 Sep 2019 14:26:56 +0000 (17:26 +0300)
As defined in HTTP/1.1, body chunks have the following ABNF:

   chunk = chunk-size [ chunk-ext ] CRLF chunk-data CRLF

where chunk-data is a sequence of chunk-size octets.

With this change, chunk-data that doesn't end up with CRLF at chunk-size
offset will be treated as invalid, such as in the example provided below:

4
SEE-THIS-AND-
4
THAT
0

src/http/ngx_http_parse.c

index d9a1dbedb59df14c25217f4e4b33009d559b990f..8e1b118529a5e2af6a544c136f5ba6106e5ba9dc 100644 (file)
@@ -2268,6 +2268,9 @@ ngx_http_parse_chunked(ngx_http_request_t *r, ngx_buf_t *b,
                 break;
             case LF:
                 state = sw_chunk_start;
+                break;
+            default:
+                goto invalid;
             }
             break;