mirror of
https://github.com/curl/curl.git
synced 2026-08-09 06:14:20 +03:00
urlapi: don't accept blank port number field without scheme
... as it makes the URL parser accept "very-long-hostname://" as a valid host name and we don't want that. The parser now only accepts a blank (no digits) after the colon if the URL starts with a scheme. Reported-by: d4d on hackerone Closes #6283
This commit is contained in:
parent
2260e0ebe6
commit
abd846c374
4 changed files with 39 additions and 18 deletions
|
|
@ -28,7 +28,7 @@
|
|||
bool Curl_is_absolute_url(const char *url, char *scheme, size_t buflen);
|
||||
|
||||
#ifdef DEBUGBUILD
|
||||
CURLUcode Curl_parse_port(struct Curl_URL *u, char *hostname);
|
||||
CURLUcode Curl_parse_port(struct Curl_URL *u, char *hostname, bool);
|
||||
#endif
|
||||
|
||||
#endif /* HEADER_CURL_URLAPI_INT_H */
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue