1
0
mirror of https://github.com/lammertb/libhttp.git synced 2026-01-28 20:00:52 +03:00

Merge pull request #176 from codyhanson/portRangeFix

Added bounds checking for listening_ports.
This commit is contained in:
Sergey Lyubka
2013-05-30 10:05:21 -07:00

View File

@@ -4291,6 +4291,8 @@ static int parse_port_string(const struct vec *vec, struct socket *so) {
} else if (sscanf(vec->ptr, "%d%n", &port, &len) != 1 ||
len <= 0 ||
len > (int) vec->len ||
port < 1 ||
port > 65535 ||
(vec->ptr[len] && vec->ptr[len] != 's' &&
vec->ptr[len] != 'r' && vec->ptr[len] != ',')) {
return 0;