| |
|
|
|
cURL Mailing List Monthly Index Single Mail
curl-and-python mailing list Archives
Re: aborting a transaction
From: Daniel Stenberg <daniel_at_haxx.se>
Date: Thu, 24 Sep 2009 05:55:58 +0200 (CEST)
On Wed, 23 Sep 2009, johansen_at_sun.com wrote:
> Perhaps I have misunderstood, but based upon your description, doesn't this
Yes. That would be an attack that libcurl itself needs counter-measures for,
libcurl does the service of putting each complete header in a buffer before it
> If the remote host sends libcurl an arbitrarily long string and the library
It's simply so that libcurl hasn't been done to safe-guard against an "attack"
lib/transfer.c:readwrite_http_headers() is the responsible function. I guess
-- / daniel.haxx.se _______________________________________________ http://cool.haxx.se/cgi-bin/mailman/listinfo/curl-and-pythonReceived on 2009-09-24 These mail archives are generated by hypermail. |
Page updated November 12, 2010.
web site info