From ce8657f12f215f910dbbce754f515baaf29f7994 Mon Sep 17 00:00:00 2001 From: Dmitry Frank Date: Tue, 30 Jan 2018 21:53:04 +0200 Subject: [PATCH] Fix corner case in preparing cgi env `path_info` was dereferenced without checking for NULL, and a few lines below, it was checked for NULL. CL: none PUBLISHED_FROM=9f14dc68c152b9b1119b276f047686d831bace38 --- mongoose.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/mongoose.c b/mongoose.c index 625e8b8a..a2b8fee6 100644 --- a/mongoose.c +++ b/mongoose.c @@ -8845,6 +8845,7 @@ static void mg_prepare_cgi_environment(struct mg_connection *nc, char *p; size_t i; char buf[100]; + size_t path_info_len = path_info != NULL ? path_info->len : 0; blk->len = blk->nvars = 0; blk->nc = nc; @@ -8876,7 +8877,7 @@ static void mg_prepare_cgi_environment(struct mg_connection *nc, mg_conn_addr_to_str(nc, buf, sizeof(buf), MG_SOCK_STRINGIFY_PORT); mg_addenv(blk, "SERVER_PORT=%s", buf); - s = hm->uri.p + hm->uri.len - path_info->len - 1; + s = hm->uri.p + hm->uri.len - path_info_len - 1; if (*s == '/') { const char *base_name = strrchr(prog, DIRSEP); mg_addenv(blk, "SCRIPT_NAME=%.*s/%s", (int) (s - hm->uri.p), hm->uri.p,