瀏覽代碼

uhttpd: fix possible CGI header line parsing beyound the empty line, thanks Linus Luessing for spotting it

SVN-Revision: 28254
Jo-Philipp Wich 14 年之前
父節點
當前提交
12bbe8b2af
共有 2 個文件被更改,包括 5 次插入5 次删除
  1. 1 1
      package/uhttpd/Makefile
  2. 4 4
      package/uhttpd/src/uhttpd-cgi.c

+ 1 - 1
package/uhttpd/Makefile

@@ -8,7 +8,7 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=uhttpd
-PKG_RELEASE:=26
+PKG_RELEASE:=27
 
 PKG_BUILD_DIR := $(BUILD_DIR)/$(PKG_NAME)
 PKG_CONFIG_DEPENDS := \

+ 4 - 4
package/uhttpd/src/uhttpd-cgi.c

@@ -1,7 +1,7 @@
 /*
  * uhttpd - Tiny single-threaded httpd - CGI handler
  *
- *   Copyright (C) 2010 Jo-Philipp Wich <[email protected]>
+ *   Copyright (C) 2010-2011 Jo-Philipp Wich <[email protected]>
  *
  *  Licensed under the Apache License, Version 2.0 (the "License");
  *  you may not use this file except in compliance with the License.
@@ -42,7 +42,7 @@ static struct http_response * uh_cgi_header_parse(char *buf, int len, int *off)
 
 		bufptr = &buf[0];
 
-		for( pos = 0; pos < len; pos++ )
+		for( pos = 0; pos < off; pos++ )
 		{
 			if( !hdrname && (buf[pos] == ':') )
 			{
@@ -60,11 +60,11 @@ static struct http_response * uh_cgi_header_parse(char *buf, int len, int *off)
 
 			else if( (buf[pos] == '\r') || (buf[pos] == '\n') )
 			{
-				buf[pos++] = 0;
-
 				if( ! hdrname )
 					break;
 
+				buf[pos++] = 0;
+
 				if( (pos < len) && (buf[pos] == '\n') )
 					pos++;