www-apache-bugdb mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Patrick Bihan-Faou <...@gandalf.com>
Subject general/2019: Stop condition on URL parsing is incorrect
Date Mon, 30 Mar 1998 21:26:34 GMT

>Number:         2019
>Category:       general
>Synopsis:       Stop condition on URL parsing is incorrect
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    apache
>State:          open
>Class:          sw-bug
>Submitter-Id:   apache
>Arrival-Date:   Mon Mar 30 13:30:01 PST 1998
>Originator:     pbf@gandalf.com
>Release:        1.2.6
Any (found while reading the code).
in the file http_protocol.c (both for versions 1.2.5 and 1.2.6),
in the function "parse_uri()", the stop condition of a loop parsing
a URI is incorrect.

This may not cause a problem in actual use sinc the loop while "break"
upon easily met conditions.

What would actually happen is the loop break at an incorrect point.
By submitting a very weird URL that would fail the checks inside the loop.
at line 515 (in version 1.2.6) replace
    for (s=uri; s != '\0'; s++)
    for (s=uri; *s != '\0'; s++)
which should be more reliable since uri is a null terminated string.
[In order for any reply to be added to the PR database, ]
[you need to include <apbugs@Apache.Org> in the Cc line ]
[and leave the subject line UNCHANGED.  This is not done]
[automatically because of the potential for mail loops. ]

View raw message