Welcome! Log In Create A New Profile

Advanced

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

agentzh
January 01, 2012 09:22AM
On Sun, Jan 1, 2012 at 1:58 PM, Justin Hart <onyxraven@gmail.com> wrote:
> Thank you for the confirmation - I read through the parts of code in
> question but wanted to get a second opinion.
>
> How about the lua and/or the perl modules?  It looks as if they are
> using the nginx functions?
>

The current released versions of ngx_lua does have this vulnerability
in its ngx.req.get_uri_args() and ngx.req.get_post_args() functions.
I've already worked out a patch for these two functions in ngx_lua's
git max-args branch here:

https://github.com/chaoslawful/lua-nginx-module/commit/75876

With this patch, both of these functions will only parse 100 query
args at most. And one can specify a custom maximum number of args
parsed with an optional function argument (default to 100) and
enforcing unlimited parsing by specifying a zero number.

This patch (as well as this branch) will be merged into the master
branch in 3 Jan.

Best,
-agentzh

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Justin Hart December 31, 2011 01:40PM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Maxim Dounin December 31, 2011 07:36PM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

agentzh January 01, 2012 12:56AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Justin Hart January 01, 2012 01:00AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

agentzh January 01, 2012 09:22AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Nginx User January 01, 2012 09:32AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Sergey A. Osokin January 01, 2012 01:40PM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

agentzh January 04, 2012 06:50AM

Re: Is nginx vulnerable to the Hash Table Vulnerability (n.runs AG)?

Nginx User January 04, 2012 03:04PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 151
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready