rtsp: deal with borked server responses

- enforce a response body length of 0, if the
  response has no Content-lenght. This is according
  to the RTSP spec.
- excess bytes in a response body are forwarded to
  the client writers which will report and fail the
  transfer

Follow-up to d7b6ce6
Fixes #12701
Closes #12706
This commit is contained in:
Stefan Eissing 2024-01-15 11:33:13 +01:00 committed by Daniel Stenberg
parent 72bd88adde
commit 036eb150d1
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
4 changed files with 68 additions and 12 deletions

View file

@ -96,7 +96,7 @@ test644 test645 test646 test647 test648 test649 test650 test651 test652 \
test653 test654 test655 test656 test658 test659 test660 test661 test662 \
test663 test664 test665 test666 test667 test668 test669 test670 test671 \
test672 test673 test674 test675 test676 test677 test678 test679 test680 \
test681 test682 test683 test684 test685 test686 test687 test688 \
test681 test682 test683 test684 test685 test686 test687 test688 test689 \
\
test700 test701 test702 test703 test704 test705 test706 test707 test708 \
test709 test710 test711 test712 test713 test714 test715 test716 test717 \

53
tests/data/test689 Normal file
View file

@ -0,0 +1,53 @@
<testcase>
#Informational
<info>
<keywords>
RTSP
OPTIONS
</keywords>
</info>
# Server-side
<reply>
<data>
RTSP/7.1 786
RTSP/
</data>
<datacheck>
</datacheck>
</reply>
# Client-Side
<client>
<server>
rtsp
</server>
<tool>
lib567
</tool>
<name>
fuzzing crash issue #12701
</name>
<command>
rtsp://%HOSTIP:%RTSPPORT/%TESTNUMBER
</command>
</client>
<verify>
<protocol>
OPTIONS rtsp://%HOSTIP:%RTSPPORT/%TESTNUMBER RTSP/1.0
CSeq: 1
User-Agent: test567
Test-Number: 567
</protocol>
# 8 == CURLE_WEIRD_SERVER_REPLY
<errorcode>
8
</errorcode>
</verify>
</testcase>