Skip to content
Commit fa3dbb9a authored by Zhouyihai Ding's avatar Zhouyihai Ding Committed by Jay Satiro
Browse files

http2: fix incorrect trailer buffer size

Prior to this change the stored byte count of each trailer was
miscalculated and 1 less than required. It appears any trailer
after the first that was passed to Curl_client_write would be truncated
or corrupted as well as the size. Potentially the size of some
subsequent trailer could be erroneously extracted from the contents of
that trailer, and since that size is used by client write an
out-of-bounds read could occur and cause a crash or be otherwise
processed by client write.

The bug appears to have been born in 0761a51e (precedes 7.49.0).

Closes https://github.com/curl/curl/pull/2231
parent 2a6dbb81
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment