From 45c7e2bc39a1620f2c853bd382175f874aa9f1bc Mon Sep 17 00:00:00 2001 From: "Evgeny Grin (Karlson2k)" Date: Mon, 7 Jun 2021 12:26:28 +0300 Subject: [PATCH] MHD_queue_response: check whether provided status code is a three digits code --- src/microhttpd/connection.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/src/microhttpd/connection.c b/src/microhttpd/connection.c index e49bfe9a..0d7ba27b 100644 --- a/src/microhttpd/connection.c +++ b/src/microhttpd/connection.c @@ -4234,6 +4234,17 @@ MHD_queue_response (struct MHD_Connection *connection, return MHD_NO; } #endif /* UPGRADE_SUPPORT */ + if ( (100 > (status_code & (~MHD_ICY_FLAG))) || + (999 < (status_code & (~MHD_ICY_FLAG))) ) + { +#ifdef HAVE_MESSAGES + MHD_DLOG (daemon, + _ ("Refused wrong status code (%u). " \ + "HTTP required three digits status code!\n"), + (status_code & (~MHD_ICY_FLAG))); +#endif + return MHD_NO; + } MHD_increment_response_rc (response); connection->response = response; connection->responseCode = status_code;