Skip to content

http-parser memory overflow

High
ireader published GHSA-hcc7-jcx2-ph95 Apr 30, 2022

Package

libhttp (c)

Affected versions

master

Patched versions

None

Description

Impact

libhttp库中,若Content-Length为负,将导致http_rawdata在通过memmove拷贝Content时产生越界问题
image

Patches

fix http-parser input memory overflow

Workarounds

预先校验Content-Length

References

@Cossack9989

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

Credits