diff --git a/changes-entries/authnz-fcgi-stderr-bound.txt b/changes-entries/authnz-fcgi-stderr-bound.txt new file mode 100644 index 00000000000..54530bb9a99 --- /dev/null +++ b/changes-entries/authnz-fcgi-stderr-bound.txt @@ -0,0 +1,3 @@ + *) mod_authnz_fcgi: Log the content of a FastCGI stderr record using its + received length instead of treating the buffer as a C string, avoiding a + read past the received bytes. [arshiya tabasum] diff --git a/modules/aaa/mod_authnz_fcgi.c b/modules/aaa/mod_authnz_fcgi.c index 7881738ed67..813dddc2ef8 100644 --- a/modules/aaa/mod_authnz_fcgi.c +++ b/modules/aaa/mod_authnz_fcgi.c @@ -629,8 +629,8 @@ static apr_status_t handle_response(const fcgi_provider_conf *conf, case AP_FCGI_STDERR: /* Text to log */ if (clen) { ap_log_rerror(APLOG_MARK, APLOG_WARNING, 0, r, - APLOGNO(02507) "%s: Logged from %s: '%s'", - fn, conf->backend, readbuf); + APLOGNO(02507) "%s: Logged from %s: '%.*s'", + fn, conf->backend, (int)readbuflen, readbuf); } if (clen > readbuflen) {