Fix out of bound access in cgi module (#11578)
When an HTTP request with a zero CONTENT_LENGTH is made, attempting to access addr(result[0]) raise an exception as the 0 index is out of bound
This commit is contained in:
parent
2a7cf71db3
commit
181350f6c9
1 changed files with 2 additions and 0 deletions
|
|
@ -77,6 +77,8 @@ proc getEncodedData(allowedMethods: set[RequestMethod]): string =
|
||||||
if methodPost notin allowedMethods:
|
if methodPost notin allowedMethods:
|
||||||
cgiError("'REQUEST_METHOD' 'POST' is not supported")
|
cgiError("'REQUEST_METHOD' 'POST' is not supported")
|
||||||
var L = parseInt(getEnv("CONTENT_LENGTH").string)
|
var L = parseInt(getEnv("CONTENT_LENGTH").string)
|
||||||
|
if L == 0:
|
||||||
|
return ""
|
||||||
result = newString(L)
|
result = newString(L)
|
||||||
if readBuffer(stdin, addr(result[0]), L) != L:
|
if readBuffer(stdin, addr(result[0]), L) != L:
|
||||||
cgiError("cannot read from stdin")
|
cgiError("cannot read from stdin")
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue