Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
V
vlc
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Redmine
Redmine
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Operations
Operations
Metrics
Environments
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
videolan
vlc
Commits
44b7c126
Commit
44b7c126
authored
Aug 25, 2014
by
Rémi Denis-Courmont
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
httpd: reject incoming requests bodies over 64k
parent
5fae41f3
Changes
1
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
5 additions
and
1 deletion
+5
-1
src/network/httpd.c
src/network/httpd.c
+5
-1
No files found.
src/network/httpd.c
View file @
44b7c126
...
...
@@ -1349,6 +1349,7 @@ static void httpd_ClientRecv(httpd_client_t *cl)
}
}
else
if
(
cl
->
query
.
i_body
>
0
)
{
/* we are reading the body of a request or a channel */
assert
(
cl
->
query
.
p_body
!=
NULL
);
i_len
=
httpd_NetRecv
(
cl
,
&
cl
->
query
.
p_body
[
cl
->
i_buffer
],
cl
->
query
.
i_body
-
cl
->
i_buffer
);
if
(
i_len
>
0
)
...
...
@@ -1541,7 +1542,10 @@ static void httpd_ClientRecv(httpd_client_t *cl)
/* TODO Mhh, handle the case where the client only
* sends a request and closes the connection to
* mark the end of the body (probably only RTSP) */
if
(
cl
->
query
.
i_body
>=
65536
)
cl
->
query
.
p_body
=
malloc
(
cl
->
query
.
i_body
);
else
cl
->
query
.
p_body
=
NULL
;
cl
->
i_buffer
=
0
;
if
(
!
cl
->
query
.
p_body
)
{
switch
(
cl
->
query
.
i_proto
)
{
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment