Fix bug in long HTTP chunk handling

Due to a copy/paste error, the start of the payload in the latest parsed
chunk was compared to chunk-length of the terminating chunk (5 chars).
So only chunks were parsed as expected, which also had a single hex
digit length.
This commit is contained in:
Kristof Havasi
2021-08-23 08:50:58 +02:00
parent f6f0e49de4
commit 4d07a99ee2
2 changed files with 2 additions and 2 deletions
+1 -1
View File
@@ -990,7 +990,7 @@ static void walkchunks(struct mg_connection *c, struct mg_http_message *hm,
char *buf2 = (char *) &c->recv.buf[reqlen];
size_t memo2 = c->recv.len;
size_t cl2 = get_chunk_length(&buf2[off], memo2 - reqlen - off, &ll);
size_t n = cl < ll + 2 ? 0 : cl2 - ll - 2;
size_t n = cl2 < ll + 2 ? 0 : cl2 - ll - 2;
memmove(buf2 + bl, buf2 + off + ll, n);
bl += n;
off += cl2;