diff options
| author | Roman Arutyunyan <arut@nginx.com> | 2026-02-26 11:52:53 +0400 |
|---|---|---|
| committer | Roman Arutyunyan <arutyunyan.roman@gmail.com> | 2026-03-24 18:46:08 +0400 |
| commit | 6f3145006b41a4ec464eed4093553a335d35e8ac (patch) | |
| tree | 70a4980776583d6e613e48d62dd8f8d901624212 /src/http/modules/ngx_http_auth_basic_module.c | |
| parent | 9739e755b8dddba82e65ca2a08d079f4c9826b75 (diff) | |
| download | nginx-6f3145006b41a4ec464eed4093553a335d35e8ac.tar.gz nginx-6f3145006b41a4ec464eed4093553a335d35e8ac.tar.bz2 | |
Mail: host validation.
Now host name resolved from client address is validated to only contain
the characters specified in RFC 1034, Section 3.5. The validation allows
to avoid injections when using the resolved host name in auth_http and
smtp proxy.
Reported by Asim Viladi Oglu Manizada, Colin Warren,
Xiao Liu (Yunnan University), Yuan Tan (UC Riverside), and
Bird Liu (Lanzhou University).
Diffstat (limited to 'src/http/modules/ngx_http_auth_basic_module.c')
0 files changed, 0 insertions, 0 deletions
