summaryrefslogtreecommitdiffhomepage
path: root/src/http/modules/ngx_http_auth_basic_module.c
diff options
context:
space:
mode:
authorRoman Arutyunyan <arut@nginx.com>2026-02-26 11:52:53 +0400
committerRoman Arutyunyan <arutyunyan.roman@gmail.com>2026-03-24 18:46:08 +0400
commit6f3145006b41a4ec464eed4093553a335d35e8ac (patch)
tree70a4980776583d6e613e48d62dd8f8d901624212 /src/http/modules/ngx_http_auth_basic_module.c
parent9739e755b8dddba82e65ca2a08d079f4c9826b75 (diff)
downloadnginx-6f3145006b41a4ec464eed4093553a335d35e8ac.tar.gz
nginx-6f3145006b41a4ec464eed4093553a335d35e8ac.tar.bz2
Mail: host validation.
Now host name resolved from client address is validated to only contain the characters specified in RFC 1034, Section 3.5. The validation allows to avoid injections when using the resolved host name in auth_http and smtp proxy. Reported by Asim Viladi Oglu Manizada, Colin Warren, Xiao Liu (Yunnan University), Yuan Tan (UC Riverside), and Bird Liu (Lanzhou University).
Diffstat (limited to 'src/http/modules/ngx_http_auth_basic_module.c')
0 files changed, 0 insertions, 0 deletions