]> git.feebdaed.xyz Git - 0xmirror/nginx.git/commit
Charset filter: improved validation of charset_map with utf-8.
authorSergey Kandaurov <pluknet@nginx.com>
Thu, 27 Feb 2025 14:42:06 +0000 (18:42 +0400)
committerpluknet <pluknet@nginx.com>
Wed, 9 Apr 2025 15:37:51 +0000 (19:37 +0400)
commita813c639211728a1441945dee149b44a0935f48b
tree2fbcd0c279f5fd84f697547c22e7702a90dffec5
parentd31305653701bd99e8e5e6aa48094599a08f9f12
Charset filter: improved validation of charset_map with utf-8.

It was possible to write outside of the buffer used to keep UTF-8
decoded values when parsing conversion table configuration.

Since this happened before UTF-8 decoding, the fix is to check in
advance if character codes are of more than 3-byte sequence.  Note
that this is already enforced by a later check for ngx_utf8_decode()
decoded values for 0xffff, which corresponds to the maximum value
encoded as a valid 3-byte sequence, so the fix does not affect the
valid values.

Found with AddressSanitizer.
Fixes GitHub issue #529.
src/http/modules/ngx_http_charset_filter_module.c