Commit 1f36e470 authored by Ruediger Pluem's avatar Ruediger Pluem
Browse files

* Fix a regression in the CVE-2011-3192 byterange fix:

  Range: bytes=-1

  Resulted in the first two bytes delivered, not in the last one.

PR: 51748
Submitted by: low_priority <lowprio20 gmail.com>
Reviewed by: rpluem


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1163985 13f79535-47bb-0310-9956-ffa450edef68
parent 98bc0818
Loading
Loading
Loading
Loading
+9 −0
Changes for CHANGES: 9 added lines, 0 removed lines.
Original line number Diff line number Diff line
                                                         -*- coding: utf-8 -*-
Changes with Apache 2.3.15

  *) Fix a regression in the CVE-2011-3192 byterange fix.
     PR 51748. [low_priority <lowprio20 gmail.com>]

  *) SECURITY: CVE-2011-3192 (cve.mitre.org)
     core: Fix handling of byte-range requests to use less memory, to avoid
     denial of service. If the sum of all ranges in a request is larger than
     the original file, ignore the ranges and send the complete file.
     PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener]

  *) core: Add MaxRanges directive to control the number of ranges permitted
     before returning the entire resource, with a default limit of 200. 
     [Eric Covener]
+1 −1
Changes for modules/http/byterange_filter.c: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -544,7 +544,7 @@ static int ap_set_byterange(request_rec *r, apr_off_t clength,
            return 0;
        }

        if (dash == range) {
        if (dash == cur) {
            /* In the form "-5" */
            if (apr_strtoff(&number, dash+1, &errp, 10) || *errp) {
                return 0;