mirror of
https://github.com/owasp-modsecurity/ModSecurity.git
synced 2026-01-13 15:07:10 +03:00
This commit is contained in:
@@ -310,7 +310,13 @@ static int multipart_process_part_header(modsec_rec *msr, char **error_msg) {
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* extract header name */
|
||||
header_name = apr_pstrmemdup(msr->mp, msr->mpd->buf, (data - msr->mpd->buf));
|
||||
if (data == msr->mpd->buf) {
|
||||
*error_msg = apr_psprintf(msr->mp, "Multipart: Invalid part header (header name missing).");
|
||||
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* extract the value value */
|
||||
data++;
|
||||
@@ -548,6 +554,7 @@ static int multipart_process_boundary(modsec_rec *msr, int last_part, char **err
|
||||
if (msr->mpd->mpp->value == NULL) return -1;
|
||||
}
|
||||
|
||||
if (msr->mpd->mpp->name) {
|
||||
/* add the part to the list of parts */
|
||||
*(multipart_part **)apr_array_push(msr->mpd->parts) = msr->mpd->mpp;
|
||||
if (msr->mpd->mpp->type == MULTIPART_FILE) {
|
||||
@@ -566,6 +573,12 @@ static int multipart_process_boundary(modsec_rec *msr, int last_part, char **err
|
||||
msr->mpd->mpp->offset, msr->mpd->mpp->length);
|
||||
}
|
||||
}
|
||||
}
|
||||
else {
|
||||
msr_log(msr, 3, "Multipart: Skipping invalid part %pp (part name missing): "
|
||||
"(offset %u, length %u)", msr->mpd->mpp,
|
||||
msr->mpd->mpp->offset, msr->mpd->mpp->length);
|
||||
}
|
||||
|
||||
msr->mpd->mpp = NULL;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user