Buffer overflow (#6817)
* Buffer overflow The host field in the web_client is to store the value of the Host HTTP header, but it is an arbitrary size and there are no length checks. I could not see an easy way to exploit it but this checks it will not overflow the buffer. * Fix warnings on @thiagoftsm build system.
Andrew Moss committed
Sep 13, 2019 at 14:38 UTC
f729ee922d9ea3557ff21b1682af1dd696c39937
1 file changed
+1
-1
web/server/web_client.c
+1
-1
@@ -791,7 +791,7 @@ static inline char *http_header_parse(struct web_client *w, char *s, int parse_u
791
w->auth_bearer_token = strdupz(v);
792
}
793
else if(hash == hash_host && !strcasecmp(s, "Host")){
794
- strncpyz(w->host, v, (ve - v));
794
+ strncpyz(w->host, v, ((size_t)(ve - v) < sizeof(w->host)-1 ? (size_t)(ve - v) : sizeof(w->host)-1));
795
}
796
#ifdef NETDATA_WITH_ZLIB
797
else if(hash == hash_accept_encoding && !strcasecmp(s, "Accept-Encoding")) {