diff options
| author | Antoine Pitrou <solipsis@pitrou.net> | 2010-12-18 18:18:21 (GMT) | 
|---|---|---|
| committer | Antoine Pitrou <solipsis@pitrou.net> | 2010-12-18 18:18:21 (GMT) | 
| commit | d7b6ac66c1b81d13f2efa8d9ebba69e17c158c0a (patch) | |
| tree | 604b45215de1d689664400edc1978f9011907b1d /Lib/httplib.py | |
| parent | c139a5683b58b0ed1f639b5da1b8a53841f71772 (diff) | |
| download | cpython-d7b6ac66c1b81d13f2efa8d9ebba69e17c158c0a.zip cpython-d7b6ac66c1b81d13f2efa8d9ebba69e17c158c0a.tar.gz cpython-d7b6ac66c1b81d13f2efa8d9ebba69e17c158c0a.tar.bz2  | |
Merged revisions 87373,87381 via svnmerge from
svn+ssh://pythondev@svn.python.org/python/branches/py3k
BaseHTTPServer isn't fixed, this would require too much refactoring.
........
  r87373 | senthil.kumaran | 2010-12-18 17:55:23 +0100 (sam., 18 déc. 2010) | 3 lines
  Fix Issue6791 - Limit the HTTP header readline with _MAXLENGTH. Patch by Antoine Pitrou
........
  r87381 | antoine.pitrou | 2010-12-18 18:59:18 +0100 (sam., 18 déc. 2010) | 3 lines
  NEWS entry for r87373
........
Diffstat (limited to 'Lib/httplib.py')
| -rw-r--r-- | Lib/httplib.py | 29 | 
1 files changed, 24 insertions, 5 deletions
diff --git a/Lib/httplib.py b/Lib/httplib.py index e1ace4d..5af0d02 100644 --- a/Lib/httplib.py +++ b/Lib/httplib.py @@ -212,6 +212,9 @@ responses = {  # maximal amount of data to read at one time in _safe_read  MAXAMOUNT = 1048576 +# maximal line length when calling readline(). +_MAXLINE = 65536 +  class HTTPMessage(mimetools.Message):      def addheader(self, key, value): @@ -274,7 +277,9 @@ class HTTPMessage(mimetools.Message):                  except IOError:                      startofline = tell = None                      self.seekable = 0 -            line = self.fp.readline() +            line = self.fp.readline(_MAXLINE + 1) +            if len(line) > _MAXLINE: +                raise LineTooLong("header line")              if not line:                  self.status = 'EOF in headers'                  break @@ -404,7 +409,10 @@ class HTTPResponse:                  break              # skip the header from the 100 response              while True: -                skip = self.fp.readline().strip() +                skip = self.fp.readline(_MAXLINE + 1) +                if len(skip) > _MAXLINE: +                    raise LineTooLong("header line") +                skip = skip.strip()                  if not skip:                      break                  if self.debuglevel > 0: @@ -563,7 +571,9 @@ class HTTPResponse:          value = []          while True:              if chunk_left is None: -                line = self.fp.readline() +                line = self.fp.readline(_MAXLINE + 1) +                if len(line) > _MAXLINE: +                    raise LineTooLong("chunk size")                  i = line.find(';')                  if i >= 0:                      line = line[:i] # strip chunk-extensions @@ -598,7 +608,9 @@ class HTTPResponse:          # read and discard trailer up to the CRLF terminator          ### note: we shouldn't have any trailers!          while True: -            line = self.fp.readline() +            line = self.fp.readline(_MAXLINE + 1) +            if len(line) > _MAXLINE: +                raise LineTooLong("trailer line")              if not line:                  # a vanishingly small number of sites EOF without                  # sending the trailer @@ -730,7 +742,9 @@ class HTTPConnection:              raise socket.error("Tunnel connection failed: %d %s" % (code,                                                                      message.strip()))          while True: -            line = response.fp.readline() +            line = response.fp.readline(_MAXLINE + 1) +            if len(line) > _MAXLINE: +                raise LineTooLong("header line")              if line == '\r\n': break @@ -1233,6 +1247,11 @@ class BadStatusLine(HTTPException):          self.args = line,          self.line = line +class LineTooLong(HTTPException): +    def __init__(self, line_type): +        HTTPException.__init__(self, "got more than %d bytes when reading %s" +                                     % (_MAXLINE, line_type)) +  # for backwards compatibility  error = HTTPException  | 
