diff options
author | Todd C. Miller <millert@cvs.openbsd.org> | 2023-11-29 15:35:08 +0000 |
---|---|---|
committer | Todd C. Miller <millert@cvs.openbsd.org> | 2023-11-29 15:35:08 +0000 |
commit | b143809d5f20c77711c72f5dc0513528a56c1548 (patch) | |
tree | d32b60ac6ec7be664588dc87ffb9354e131961da /etc | |
parent | f5c218f0b0f80ee4042ab5df857649f8bae0b4d1 (diff) |
relay_read_http: defer header parsing until after line continuation
Wait until we have a complete line before parsing the Content-Length,
Transfer-Encoding and Host headers. This prevents potential request
smuggling attacks. Filtering already happens after header line
continuation has been performed. Reported by Ben Kallus.
OK claudio@
Diffstat (limited to 'etc')
0 files changed, 0 insertions, 0 deletions