[ 
https://issues.apache.org/jira/browse/TS-827?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Leif Hedstrom updated TS-827:
-----------------------------

    Backport to Version: 3.0.0
          Fix Version/s: 3.0.0
                         3.1.0

marking this for backporting to 3.0.0, since it's potentially a buffer overflow 
issue for plugins. This code should be cleaned up later, but I think amc is 
going to look at it later, and for now this is good enough.

Thanks William!

> TSMimeHdrFieldValueStringInsert() can use freed memory to edit headers
> ----------------------------------------------------------------------
>
>                 Key: TS-827
>                 URL: https://issues.apache.org/jira/browse/TS-827
>             Project: Traffic Server
>          Issue Type: Bug
>          Components: MIME
>    Affects Versions: 2.1.9, 2.1.8, 2.1.7, 2.1.6, 2.1.5, 2.1.4
>            Reporter: William Bardwell
>            Assignee: Leif Hedstrom
>             Fix For: 3.1.0, 3.0.0
>
>         Attachments: headers-prealloc.diff
>
>
> TSMimeHdrFieldValueStringInsert() and other TSMimeHdrFieldValue*() APIs can 
> use freed memory to edit headers
> due to calling HdrHeap::coalesce_str_heaps() from HdrHeap::allocate_str() from
> mime_field_value_insert_comma_val() and other mime_field_value_*comma_val() 
> functions while holding pointers
> into the HdrHeap.
> I have a hacky but functional patch for this.

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira

Reply via email to