summaryrefslogtreecommitdiff
path: root/netwerk
diff options
context:
space:
mode:
authorwolfbeast <mcwerewolf@wolfbeast.com>2019-07-20 13:59:45 +0200
committerwolfbeast <mcwerewolf@wolfbeast.com>2019-07-20 13:59:45 +0200
commit1c40d51b7214f92f6ea2d0aa89b53310ecb3b74c (patch)
tree5bbf3a9fe7b75d73d69e3020f47523e8f61b6333 /netwerk
parent186e9d08d3ed6f625c204e79a2f44abb27b25e9f (diff)
downloaduxp-1c40d51b7214f92f6ea2d0aa89b53310ecb3b74c.tar.gz
Check port safety for AltSvc
Diffstat (limited to 'netwerk')
-rw-r--r--netwerk/protocol/http/AlternateServices.cpp5
1 files changed, 5 insertions, 0 deletions
diff --git a/netwerk/protocol/http/AlternateServices.cpp b/netwerk/protocol/http/AlternateServices.cpp
index ee2fa9331c..10bd619289 100644
--- a/netwerk/protocol/http/AlternateServices.cpp
+++ b/netwerk/protocol/http/AlternateServices.cpp
@@ -121,6 +121,11 @@ AltSvcMapping::ProcessHeader(const nsCString &buf, const nsCString &originScheme
continue;
}
+ if (NS_FAILED(NS_CheckPortSafety(portno, originScheme.get()))) {
+ LOG(("Alt Svc does not allow port %d, ignoring request", portno));
+ continue;
+ }
+
// unescape modifies a c string in place, so afterwards
// update nsCString length
nsUnescape(npnToken.BeginWriting());