Re: cvs: php4 / configure.in /sapi/cgi README.FastCGI cgi_main.c config9.m4 /sapi/cgi/libfcgi fcgiapp.c os_unix.c /sapi/cgi/libfcgi/include
fcgi_config.h fcgi_config_win32.h fcgios.h
| From: | Edin Kadribasic | Date: | Tue, 26 Nov 2002 09:42:37 +0000 |
| Subject: | Re: cvs: php4 / configure.in /sapi/cgi README.FastCGI cgi_main.c config9.m4 /sapi/cgi/libfcgi fcgiapp.c os_unix.c /sapi/cgi/libfcgi/include fcgi_config.h fcgi_config_win32.h fcgios.h |
||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-16665@lists.php.net to get a copy of this message | ||
> Another thing i saw in cgi:
> len = snprintf(buf,
SAPI_CGI_MAX_HEADER_LENGTH,
> "%s\r\n",
> SG(sapi_headers).http_status_line);
>
> if (len > SAPI_CGI_MAX_HEADER_LENGTH) {
> len = SAPI_CGI_MAX_HEADER_LENGTH;
> }
>
> The problem here is that the headers could be cut of so that
"\r\n" is lost.
> As this is needed i suggest the following patch. Please check it
since i am
> not sure if it is really correct (the question is length
calculation/and sorry
> for not having the time to check myself).
Hi Marcus,
I did this last week and I dont think there is need to fix it. It
only applies to HTTP/1.x response code headers and those can hardly
be 1K in length. I only put the check to prevent intentional misuse
(buffer overflow) which cannot happen in noram use situatuion.
Edin