Commit Graph
5352 Commits
Author SHA1 Message Date
Christian Grothoff a1fb82fc3c more findings 2026-07-28 17:04:14 +02:00
Christian Grothoff 07c051dd7e fail MHD_digest_auth_check_digest2 on MHD_DIGEST_ALG_AUTO 2026-07-28 16:58:41 +02:00
Christian Grothoff acef58a077 prevent connection upgrade attempts on connections that must-close 2026-07-28 16:57:45 +02:00
Christian Grothoff d0270f583a expand fuzzer coverage 2026-07-28 16:56:42 +02:00
Christian Grothoff 1b7b319d04 fix fuzzer setup logic 2026-07-28 13:50:17 +02:00
Christian Grothoff 6e43206ba1 version bumping, this time correctly 2026-07-28 12:40:05 +02:00
Christian Grothoff e34baa3f1a expand test suite, add CI/CD logic as done in other GNUnet projects 2026-07-28 12:36:36 +02:00
Christian Grothoff b4f2b6583f fix spelling 2026-07-28 11:40:40 +02:00
Christian Grothoff 2a9c4676ed fix bogus assertion 2026-07-28 11:06:10 +02:00
Christian Grothoff 6fcdfd437e fix bogus assertion 2026-07-28 11:03:00 +02:00
Christian Grothoff 0b7509755f fix bogus assertion 2026-07-28 11:02:27 +02:00
Christian Grothoff e04eb2189b add missing return to ensure 413 is given to client 2026-07-28 11:01:37 +02:00
Christian Grothoff 68c83f22b8 fix bogus assertion 2026-07-28 11:00:28 +02:00
Christian Grothoff 300a2ab01c handle empty username and empty realm provided by client gracefully 2026-07-28 10:59:19 +02:00
Christian Grothoff 888606e004 fix algorithm parsing, string cmp was matching wrong strings to client requests to determine selected algorithm 2026-07-28 10:58:39 +02:00
Christian Grothoff f438804c18 do not abort on nonce slot collisions with different algorithms 2026-07-28 10:55:44 +02:00
Christian Grothoff 3b898eaea7 fix another issue with INVALID enum check where masking did not work because INVALID is zero 2026-07-28 10:53:07 +02:00
Christian Grothoff fc353cf059 release v1.0.7 v1.0.7 2026-07-27 18:14:11 +02:00
Christian Grothoff 5a73c1ae81 ensure digest authentication hex decoder does not overflow if give hex-encoded userhash is too long (potential out-of-bounds stack write); thanks to A. Ramos for reporting 2026-07-27 18:11:25 +02:00
Christian Grothoff c13f4c6484 fix parsing of chunk-extension lines that previously failed to skip the \r\n properly; might be abused for HTTP request smuggling; thanks to A. Ramos for reporting 2026-07-27 18:00:30 +02:00
Christian Grothoff 29eaa56b31 fix read-buffer shift back underflow in special conditionas with trailing query arguments without '='; thanks to A. Ramos for reporting 2026-07-27 17:55:00 +02:00
Christian Grothoff bd49ce930b fix missing check for MHD_DIGEST_AUTH_ALGO3_INVALID case reported by A. Ramos that could result in an abort 2026-07-27 17:42:50 +02:00
Christian Grothoff 24872e88ff POT update 2026-07-27 17:42:33 +02:00
Christian Grothoff 0f23455719 update NEWS v1.0.6 2026-07-08 12:48:44 +02:00
Christian Grothoff 6a3d1006b8 bump version to v1.0.6 2026-07-08 12:45:21 +02:00
Christian Grothoff f2af9bc474 -DCE 2026-07-08 12:20:14 +02:00
Christian Grothoff 592c70648b -typos 2026-07-08 12:17:59 +02:00
Christian Grothoff 026525d584 match content-type only at beginning of the line 2026-07-08 12:12:58 +02:00
Christian Grothoff d6fc384fc4 fix overflow check 2026-07-08 12:11:26 +02:00
Christian Grothoff f10d7c71ab fix overflow check 2026-07-08 12:09:38 +02:00
Christian Grothoff b4165ecc09 fix overflow check 2026-07-08 12:07:51 +02:00
Christian Grothoff df2309b0ed fix theoretical div by 0 2026-07-08 12:06:19 +02:00
Christian Grothoff 9a1527ff72 fix CLOSE flag test 2026-07-08 12:03:13 +02:00
Christian Grothoff 5abfcc927a add assertion to prevent underflow 2026-07-08 11:56:37 +02:00
Christian Grothoff 97b4296cc0 fix possible underflow on timeout computation 2026-07-08 11:54:11 +02:00
Christian Grothoff e5f88887df size check before allocating 2026-07-08 11:51:55 +02:00
Christian Grothoff b2752fc496 fix allocation type 2026-07-08 11:49:31 +02:00
Christian Grothoff de88b6724a check bound before writing in test 2026-07-08 11:45:28 +02:00
Christian Grothoff 04547cd9c8 use proper guards to avoid (theoretical) off-by-one in pct decoding 2026-07-08 11:42:33 +02:00
Christian Grothoff 2a6420de23 use caseless cmp as per function name and spec 2026-07-08 11:40:26 +02:00
Christian Grothoff 06cd63df36 limit to INT_MAX, not UINT_MAX 2026-07-08 11:37:55 +02:00
Christian Grothoff 83eecbca49 add NULL check 2026-07-08 11:37:01 +02:00
Christian Grothoff b7dd720a32 fix oversized array 2026-07-08 11:36:24 +02:00
Christian Grothoff 930e236ea3 fix OOM handling 2026-07-08 11:34:32 +02:00
Christian Grothoff d3c3ea0b8a fix OOM handling 2026-07-08 11:33:51 +02:00
Christian Grothoff 679fb11892 fix swapped conditions in poll() for upgraded socket 2026-07-08 11:32:58 +02:00
Christian Grothoff 3704914ccd remove duplicated mutex destroy 2026-07-08 11:31:13 +02:00
Christian Grothoff d2375954a1 releasing v1.0.5 v1.0.5 2026-04-16 10:38:04 +02:00
Evgeny Grin (Karlson2k) 9933d65464 Tighten request header processing to match RFC
New implementation:
+ rejects repeated Host: headers
+ handles repeated Content-Length: more carefully
+ handles malformed Content-Length: better
+ handles repeated Transfer-Encoding: headers
+ parses all Cookie: headers instead of just first header
+ handles properly Transfer-Encoding: in HTTP/1.0 requests
2026-04-15 21:35:12 +02:00
Evgeny Grin (Karlson2k) a7f6ad8f4f test_mhd_version.c: corrected output 2026-04-14 19:55:27 +02:00