Welcome! Log In Create A New Profile

Advanced

Re: Heap buffer overflow (read) when using $binary_remote_addr with unix sockets

Sergey Kandaurov
September 20, 2017 09:22AM
> On 15 Aug 2017, at 13:10, Stephan Dollberg via nginx-devel <nginx-devel@nginx.org> wrote:
>
> Hi,
>
> When using $binary_remote_addr together with unix sockets (without
> using X-Real-Ip) there is a heap buffer overread of two bytes.
>
> The problem is that we only allocate two bytes for c->sockaddr here
> http://hg.nginx.org/nginx/file/tip/src/event/ngx_event_accept.c#l167
> but later on assume it to be of size four
> http://hg.nginx.org/nginx/file/tip/src/http/ngx_http_variables.c#l1246
>
>

Thanks, this is a valid report.
The reason is that UNIX-domain sockets support
is not implemented for $binary_remote_addr.
There are actually more issues, we are working on it.

--
Sergey Kandaurov

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

Heap buffer overflow (read) when using $binary_remote_addr with unix sockets

Stephan Dollberg via nginx-devel 575 August 15, 2017 06:12AM

Re: Heap buffer overflow (read) when using $binary_remote_addr with unix sockets

Sergey Kandaurov 183 September 20, 2017 09:22AM

Re: Heap buffer overflow (read) when using $binary_remote_addr with unix sockets

Maxim Dounin 208 October 04, 2017 03:12PM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 201
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready