Skip to content

mod_authnz_fcgi: log FastCGI stderr using the received length - #779

Open
arshsmith1 wants to merge 1 commit into
apache:trunkfrom
arshsmith1:authnz-fcgi-stderr-bound
Open

arshsmith1 wants to merge 1 commit into
apache:trunkfrom
arshsmith1:authnz-fcgi-stderr-bound

Conversation

@arshsmith1

Copy link
Copy Markdown

handle_response reads an AP_FCGI_STDERR record into readbuf via recv_data (apr_socket_recv), which stores exactly readbuflen bytes and does not NUL-terminate it, but the log call then formats readbuf with %s and keeps reading past those bytes into the uninitialized stack buffer, and off the end of it when the content has no NUL. The sibling mod_proxy_fcgi already logs its stderr record with '%.*s' and (int)readbuflen, so this matches that here. Any stderr output from the configured authorizer reaches this path, and the trailing bytes land in the error log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant