[Bug 2105085] perl-HTTP-Daemon: HTTP::Daemon allows request smuggling

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=2105085

amctagga@xxxxxxxxxx changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
            Comment|0                           |updated



--- Comment #0 has been edited ---



HTTP::Daemon is a simple http server class written in perl. Versions prior to
6.15 are subject to a vulnerability which could potentially be exploited to
gain privileged access to APIs or poison intermediate caches. It is uncertain
how large the risks are, most Perl based applications are served on top of
Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for
local development and tests. Users are advised to update to resolve this issue.
Users unable to upgrade may add additional request handling logic as a
mitigation. After calling `my $rqst = $conn->get_request()` one could inspect
the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl =
$rqst->header('Content-Length')`) will show any abnormalities that should be
dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD
consist of either a single non-negative integer, or, a comma separated
repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST
be rejected.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2105085
_______________________________________________
perl-devel mailing list -- perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to perl-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure




[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Legacy Announce]     [Fedora PHP Devel]     [Kernel Devel]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite Information]

  Powered by Linux