public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Kaleb S. KEITHLEY <kkeithle@redhat.com>
To: git-commits@fedoraproject.org
Subject: [rpms/civetweb] f43: civetweb-1.16, rhbz 2400162-2400166
Date: Fri, 07 Aug 2026 18:19:23 GMT	[thread overview]
Message-ID: <178612676389.1.8205842575987258695.rpms-civetweb-208bae079754@fedoraproject.org> (raw)

A new commit has been pushed.

Repo   : rpms/civetweb
Branch : f43
Commit : 208bae0797549d2ef6178a7d619ae08078173dde
Author : Kaleb S. KEITHLEY <kkeithle@redhat.com>
Date   : 2025-09-29T15:32:18-04:00
Stats  : +250/-40 in 3 file(s)
URL    : https://src.fedoraproject.org/rpms/civetweb/c/208bae0797549d2ef6178a7d619ae08078173dde?branch=f43

Log:
civetweb-1.16, rhbz 2400162-2400166

---
diff --git a/0002-src-civetweb.c.patch b/0002-src-civetweb.c.patch
index fc3a024..c66b622 100644
--- a/0002-src-civetweb.c.patch
+++ b/0002-src-civetweb.c.patch
@@ -7,11 +7,9 @@ Subject: [PATCH 1/2] Fix heap overflow in directory URI slash redirection
  src/civetweb.c | 23 ++++++++++++++++++-----
  1 file changed, 18 insertions(+), 5 deletions(-)
 
-diff --git a/src/civetweb.c b/src/civetweb.c
-index bbc9aa8be..e969c939f 100644
---- a/src/civetweb.c
-+++ b/src/civetweb.c
-@@ -15579,7 +15579,6 @@ handle_request(struct mg_connection *conn)
+--- civetweb-1.16/src/civetweb.c.orig	2023-04-08 11:38:36.000000000 -0400
++++ civetweb-1.16/src/civetweb.c	2025-09-29 15:08:02.385060903 -0400
+@@ -15242,7 +15242,6 @@
  	/* 12. Directory uris should end with a slash */
  	if (file.stat.is_directory && ((uri_len = (int)strlen(ri->local_uri)) > 0)
  	    && (ri->local_uri[uri_len - 1] != '/')) {
@@ -19,7 +17,7 @@ index bbc9aa8be..e969c939f 100644
  		/* Path + server root */
  		size_t buflen = UTF8_PATH_MAX * 2 + 2;
  		char *new_path;
-@@ -15592,12 +15591,26 @@ handle_request(struct mg_connection *conn)
+@@ -15255,12 +15254,26 @@
  			mg_send_http_error(conn, 500, "out or memory");
  		} else {
  			mg_get_request_link(conn, new_path, buflen - 1);
@@ -29,7 +27,7 @@ index bbc9aa8be..e969c939f 100644
 +			if (len + 1 < buflen) {
 +				new_path[len] = '/';
 +				new_path[len + 1] = '\0';
-+				len += 1;
++				len++;
 +			}
 +
  			if (ri->query_string) {
@@ -39,7 +37,7 @@ index bbc9aa8be..e969c939f 100644
 +				if (len + 1 < buflen) {
 +					new_path[len] = '?';
 +					new_path[len + 1] = '\0';
-+					len += 1;
++					len++;
 +				}
 +
 +				/* Append with size of space left for query string + null terminator */
@@ -50,34 +48,3 @@ index bbc9aa8be..e969c939f 100644
  			mg_send_http_redirect(conn, new_path, 301);
  			mg_free(new_path);
  		}
-
-From d5321963b1d0bc953101de91f8588bf83db73bf5 Mon Sep 17 00:00:00 2001
-From: krispybyte <krispybyte@proton.me>
-Date: Sun, 22 Jun 2025 00:23:06 +0300
-Subject: [PATCH 2/2] Fit code style
-
----
- src/civetweb.c | 4 ++--
- 1 file changed, 2 insertions(+), 2 deletions(-)
-
-diff --git a/src/civetweb.c b/src/civetweb.c
-index e969c939f..6af91f874 100644
---- a/src/civetweb.c
-+++ b/src/civetweb.c
-@@ -15596,14 +15596,14 @@ handle_request(struct mg_connection *conn)
- 			if (len + 1 < buflen) {
- 				new_path[len] = '/';
- 				new_path[len + 1] = '\0';
--				len += 1;
-+				len++;
- 			}
- 
- 			if (ri->query_string) {
- 				if (len + 1 < buflen) {
- 					new_path[len] = '?';
- 					new_path[len + 1] = '\0';
--					len += 1;
-+					len++;
- 				}
- 
- 				/* Append with size of space left for query string + null terminator */

diff --git a/0003-src-civetweb.c.patch b/0003-src-civetweb.c.patch
new file mode 100644
index 0000000..36ebb53
--- /dev/null
+++ b/0003-src-civetweb.c.patch
@@ -0,0 +1,239 @@
+From 782e18903515f43bafbf2e668994e82bdfa51133 Mon Sep 17 00:00:00 2001
+From: bel2125 <bel2125@gmail.com>
+Date: Tue, 2 Sep 2025 14:08:41 +0200
+Subject: [PATCH] Make parsing of URL encoded forms more robust
+
+Reject requests that obviously violate the URL encoding.
+Fixes #1348
+---
+ src/civetweb.c      |  7 ++++++-
+ src/handle_form.inl | 46 +++++++++++++++++++++++++++++++++++++--------
+ 2 files changed, 44 insertions(+), 9 deletions(-)
+
+--- civetweb-1.16/src/civetweb.c.orig	2025-09-29 15:08:02.385060903 -0400
++++ civetweb-1.16/src/civetweb.c	2025-09-29 15:09:30.128628855 -0400
+@@ -7052,6 +7052,7 @@
+               int is_form_url_encoded)
+ {
+ 	int i, j, a, b;
++
+ #define HEXTOI(x) (isdigit(x) ? (x - '0') : (x - 'W'))
+ 
+ 	for (i = j = 0; (i < src_len) && (j < (dst_len - 1)); i++, j++) {
+@@ -7064,11 +7065,15 @@
+ 			i += 2;
+ 		} else if (is_form_url_encoded && (src[i] == '+')) {
+ 			dst[j] = ' ';
++		} else if ((unsigned char)src[i] <= ' ') {
++			return -1; /* invalid character */
+ 		} else {
+ 			dst[j] = src[i];
+ 		}
+ 	}
+ 
++#undef HEXTOI
++
+ 	dst[j] = '\0'; /* Null-terminate the destination */
+ 
+ 	return (i >= src_len) ? j : -1;
+--- ./src/handle_form.inl.orig	2023-04-08 11:38:36.000000000 -0400
++++ ./src/handle_form.inl	2025-09-29 15:09:30.130628822 -0400
+@@ -1,4 +1,4 @@
+-/* Copyright (c) 2016-2021 the Civetweb developers
++/* Copyright (c) 2016-2025 the Civetweb developers
+  *
+  * Permission is hereby granted, free of charge, to any person obtaining a copy
+  * of this software and associated documentation files (the "Software"), to deal
+@@ -39,7 +39,7 @@
+ 	    mg_url_decode(key, (int)key_len, key_dec, (int)sizeof(key_dec), 1);
+ 
+ 	if (((size_t)key_dec_len >= (size_t)sizeof(key_dec)) || (key_dec_len < 0)) {
+-		return MG_FORM_FIELD_STORAGE_SKIP;
++		return MG_FORM_FIELD_STORAGE_ABORT;
+ 	}
+ 
+ 	if (filename) {
+@@ -53,7 +53,7 @@
+ 		    || (filename_dec_len < 0)) {
+ 			/* Log error message and skip this field. */
+ 			mg_cry_internal(conn, "%s: Cannot decode filename", __func__);
+-			return MG_FORM_FIELD_STORAGE_SKIP;
++			return MG_FORM_FIELD_STORAGE_ABORT;
+ 		}
+ 		remove_dot_segments(filename_dec);
+ 
+@@ -95,6 +95,7 @@
+     struct mg_form_data_handler *fdh)
+ {
+ 	char key_dec[1024];
++	int key_dec_len;
+ 
+ 	char *value_dec = (char *)mg_malloc_ctx(*value_len + 1, conn->phys_ctx);
+ 	int value_dec_len, ret;
+@@ -108,7 +109,8 @@
+ 		return MG_FORM_FIELD_STORAGE_ABORT;
+ 	}
+ 
+-	mg_url_decode(key, (int)key_len, key_dec, (int)sizeof(key_dec), 1);
++	key_dec_len = mg_url_decode(
++	    key, (int)key_len, key_dec, (int)sizeof(key_dec), 1);
+ 
+ 	if (*value_len >= 2 && value[*value_len - 2] == '%')
+ 		*value_len -= 2;
+@@ -117,6 +119,11 @@
+ 	value_dec_len = mg_url_decode(
+ 	    value, (int)*value_len, value_dec, ((int)*value_len) + 1, 1);
+ 
++	if ((key_dec_len < 0) || (value_dec_len < 0)) {
++		mg_free(value_dec);
++		return MG_FORM_FIELD_STORAGE_ABORT;
++	}
++
+ 	ret = fdh->field_get(key_dec,
+ 	                     value_dec,
+ 	                     (size_t)value_dec_len,
+@@ -136,9 +143,13 @@
+                     struct mg_form_data_handler *fdh)
+ {
+ 	char key_dec[1024];
++	int key_dec_len;
+ 	(void)conn;
+ 
+-	mg_url_decode(key, (int)key_len, key_dec, (int)sizeof(key_dec), 1);
++	key_dec_len = mg_url_decode(key, (int)key_len, key_dec, (int)sizeof(key_dec), 1);
++	if (key_dec_len < 0) {
++		return MG_FORM_FIELD_STORAGE_ABORT;
++	}
+ 
+ 	return fdh->field_get(key_dec, value, value_len, fdh->user_data);
+ }
+@@ -188,6 +199,7 @@
+ 	int buf_fill = 0;
+ 	int r;
+ 	int field_count = 0;
++	int abort_read = 0;
+ 	struct mg_file fstore = STRUCT_FILE_INITIALIZER;
+ 	int64_t file_size = 0; /* init here, to a avoid a false positive
+ 	                         "uninitialized variable used" warning */
+@@ -278,6 +290,7 @@
+ 				    conn, data, (size_t)keylen, val, (size_t *)&vallen, fdh);
+ 				if (r == MG_FORM_FIELD_HANDLE_ABORT) {
+ 					/* Stop request handling */
++					abort_read = 1;
+ 					break;
+ 				}
+ 				if (r == MG_FORM_FIELD_HANDLE_NEXT) {
+@@ -320,6 +333,7 @@
+ 							r = field_stored(conn, path, file_size, fdh);
+ 							if (r == MG_FORM_FIELD_HANDLE_ABORT) {
+ 								/* Stop request handling */
++								abort_read = 1;
+ 								break;
+ 							}
+ 
+@@ -358,6 +372,7 @@
+ 			if ((field_storage & MG_FORM_FIELD_STORAGE_ABORT)
+ 			    == MG_FORM_FIELD_STORAGE_ABORT) {
+ 				/* Stop parsing the request */
++				abort_read = 1;
+ 				break;
+ 			}
+ 
+@@ -386,7 +401,7 @@
+ 		 * Here we use "POST", and read the data from the request body.
+ 		 * The data read on the fly, so it is not required to buffer the
+ 		 * entire request in memory before processing it. */
+-		for (;;) {
++		while (!abort_read) {
+ 			const char *val;
+ 			const char *next;
+ 			ptrdiff_t keylen, vallen;
+@@ -440,6 +455,7 @@
+ 			if ((field_storage & MG_FORM_FIELD_STORAGE_ABORT)
+ 			    == MG_FORM_FIELD_STORAGE_ABORT) {
+ 				/* Stop parsing the request */
++				abort_read = 1;
+ 				break;
+ 			}
+ 
+@@ -468,6 +484,15 @@
+ 				} else {
+ 					vallen = (ptrdiff_t)strlen(val);
+ 					end_of_key_value_pair_found = all_data_read;
++					if ((buf + buf_fill) > (val + vallen)) {
++						/* Avoid DoS attacks by having a zero byte in the middle of
++						 * a request that is supposed to be URL encoded. Since this
++						 * request is certainly invalid, according to the protocol
++						 * specification, stop processing it. Fixes #1348 */
++						abort_read = 1;
++						break;
++					}
++
+ 				}
+ 
+ 				if (field_storage == MG_FORM_FIELD_STORAGE_GET) {
+@@ -489,6 +514,7 @@
+ 					get_block++;
+ 					if (r == MG_FORM_FIELD_HANDLE_ABORT) {
+ 						/* Stop request handling */
++						abort_read = 1;
+ 						break;
+ 					}
+ 					if (r == MG_FORM_FIELD_HANDLE_NEXT) {
+@@ -557,7 +583,6 @@
+ 						val = buf;
+ 					}
+ 				}
+-
+ 			} while (!end_of_key_value_pair_found);
+ 
+ #if !defined(NO_FILESYSTEMS)
+@@ -568,6 +593,7 @@
+ 					r = field_stored(conn, path, file_size, fdh);
+ 					if (r == MG_FORM_FIELD_HANDLE_ABORT) {
+ 						/* Stop request handling */
++						abort_read = 1;
+ 						break;
+ 					}
+ 				} else {
+@@ -581,7 +607,7 @@
+ 			}
+ #endif /* NO_FILESYSTEMS */
+ 
+-			if (all_data_read && (buf_fill == 0)) {
++			if ((all_data_read && (buf_fill == 0)) || abort_read) {
+ 				/* nothing more to process */
+ 				break;
+ 			}
+@@ -937,6 +963,7 @@
+ 					get_block++;
+ 					if (r == MG_FORM_FIELD_HANDLE_ABORT) {
+ 						/* Stop request handling */
++						abort_read = 1;
+ 						break;
+ 					}
+ 					if (r == MG_FORM_FIELD_HANDLE_NEXT) {
+@@ -1011,6 +1038,7 @@
+ 				                        fdh);
+ 				if (r == MG_FORM_FIELD_HANDLE_ABORT) {
+ 					/* Stop request handling */
++					abort_read = 1;
+ 					break;
+ 				}
+ 				if (r == MG_FORM_FIELD_HANDLE_NEXT) {
+@@ -1039,6 +1067,7 @@
+ 							r = field_stored(conn, path, file_size, fdh);
+ 							if (r == MG_FORM_FIELD_HANDLE_ABORT) {
+ 								/* Stop request handling */
++								abort_read = 1;
+ 								break;
+ 							}
+ 						} else {
+@@ -1057,6 +1086,7 @@
+ 			if ((field_storage & MG_FORM_FIELD_STORAGE_ABORT)
+ 			    == MG_FORM_FIELD_STORAGE_ABORT) {
+ 				/* Stop parsing the request */
++				abort_read = 1;
+ 				break;
+ 			}
+ 

diff --git a/civetweb.spec b/civetweb.spec
index 2b28a2e..fdcde47 100644
--- a/civetweb.spec
+++ b/civetweb.spec
@@ -4,12 +4,13 @@
 Name:           civetweb
 Summary:        Embedded C/C++ web server
 Version:        1.16
-Release:        9%{?dev:%{dev}}%{?dist}
+Release:        10%{?dev:%{dev}}%{?dist}
 License:        MIT
 Url:            https://github.com/civetweb/civetweb
 Source:         https://github.com/%{name}/%{name}/archive/v%{version}/%{name}-%{version}.tar.gz
 Patch:		0001-CMakeLists.txt.patch
 Patch:		0002-src-civetweb.c.patch
+Patch:		0003-src-civetweb.c.patch
 BuildRequires:  cmake make gcc-c++
 
 %description
@@ -63,6 +64,9 @@ mkdir -p %{buildroot}%{_docdir}/civetweb
 %{_datadir}/pkgconfig/*
 
 %changelog
+* Mon Sep 29 2025 Kaleb S. KEITHLEY <kkeithle at redhat.com> - 1.16-10
+- civetweb 1.16, rhbz 2400162-2400166
+
 * Wed Sep 3 2025 Kaleb S. KEITHLEY <kkeithle at redhat.com> - 1.16-9
 - civetweb 1.16
 

                 reply	other threads:[~2026-08-07 18:19 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178612676389.1.8205842575987258695.rpms-civetweb-208bae079754@fedoraproject.org \
    --to=kkeithle@redhat.com \
    --cc=git-commits@fedoraproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox