summaryrefslogtreecommitdiffhomepage
path: root/docs
diff options
context:
space:
mode:
authorSergey Kandaurov <pluknet@nginx.com>2026-03-18 16:39:37 +0400
committerRoman Arutyunyan <arutyunyan.roman@gmail.com>2026-03-24 18:46:36 +0400
commit9bc13718fe8a59a4538805516be7e141070c22d6 (patch)
tree21643aa64fc24908ce1b3f9a3357155740a5fbf8 /docs
parent6f3145006b41a4ec464eed4093553a335d35e8ac (diff)
downloadnginx-9bc13718fe8a59a4538805516be7e141070c22d6.tar.gz
nginx-9bc13718fe8a59a4538805516be7e141070c22d6.tar.bz2
Mail: fixed clearing s->passwd in auth http requests.
Previously, it was not properly cleared retaining length as part of authenticating with CRAM-MD5 and APOP methods that expect to receive password in auth response. This resulted in null pointer dereference and worker process crash in subsequent auth attempts with CRAM-MD5. Reported by Arkadi Vainbrand.
Diffstat (limited to 'docs')
0 files changed, 0 insertions, 0 deletions