tool_cb_hdr: add an additional parsing check #12320
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
As 'p' is advanced it can point to the past-the-end element and prior to this change 'p' could be dereferenced in that case.
Technically the past-the-end element is not out of bounds because dynbuf (which manages the header line) automatically adds a null terminator to every buffer and that is not included in the buffer length passed to the header callback.
Closes #xxxxx
to force past-the-end dereference set server content-disposition header to max length (102399).
note 102399 comes from CURL_MAX_HTTP_HEADER which is 102400 minus the 1 byte dynbuf uses at the end of every buffer to null terminate. if the server sent a length of 102400 for the header then dynbuf returns out of memory. due to this an access violation is not possible.