mirror of
https://github.com/curl/curl.git
synced 2026-08-25 09:43:32 +03:00
urlapi: stricter CURLUPART_PORT parsing
Only allow well formed decimal numbers in the input. Document that the number MUST be between 1 and 65535. Add tests to test 1560 to verify the above. Ref: https://github.com/curl/curl/issues/3753 Closes #3762
This commit is contained in:
parent
79c4864a56
commit
d715d2ac89
3 changed files with 80 additions and 33 deletions
11
lib/urlapi.c
11
lib/urlapi.c
|
|
@ -1145,6 +1145,7 @@ CURLUcode curl_url_set(CURLU *u, CURLUPart what,
|
|||
storep = &u->host;
|
||||
break;
|
||||
case CURLUPART_PORT:
|
||||
u->portnum = 0;
|
||||
storep = &u->port;
|
||||
break;
|
||||
case CURLUPART_PATH:
|
||||
|
|
@ -1188,12 +1189,18 @@ CURLUcode curl_url_set(CURLU *u, CURLUPart what,
|
|||
storep = &u->host;
|
||||
break;
|
||||
case CURLUPART_PORT:
|
||||
{
|
||||
char *endp;
|
||||
urlencode = FALSE; /* never */
|
||||
port = strtol(part, NULL, 10); /* Port number must be decimal */
|
||||
port = strtol(part, &endp, 10); /* Port number must be decimal */
|
||||
if((port <= 0) || (port > 0xffff))
|
||||
return CURLUE_BAD_PORT_NUMBER;
|
||||
if(*endp)
|
||||
/* weirdly provided number, not good! */
|
||||
return CURLUE_MALFORMED_INPUT;
|
||||
storep = &u->port;
|
||||
break;
|
||||
}
|
||||
break;
|
||||
case CURLUPART_PATH:
|
||||
urlskipslash = TRUE;
|
||||
storep = &u->path;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue