diff options
author | Nick Mathewson <nickm@torproject.org> | 2012-03-08 21:09:34 -0500 |
---|---|---|
committer | Nick Mathewson <nickm@torproject.org> | 2012-05-16 12:14:48 -0400 |
commit | 1abe533b3304619bd8c59f170097ab469af99dc9 (patch) | |
tree | c4be4391d89f0e7958378a9203cdc3cf9ccad1b2 | |
parent | d0d9c3d71e1fb88557d684c59cf8a920712b16f1 (diff) | |
download | tor-1abe533b3304619bd8c59f170097ab469af99dc9.tar.gz tor-1abe533b3304619bd8c59f170097ab469af99dc9.zip |
Reject an additional type of bad date in parse_http_time
-rw-r--r-- | src/common/util.c | 5 | ||||
-rw-r--r-- | src/test/test_util.c | 1 |
2 files changed, 5 insertions, 1 deletions
diff --git a/src/common/util.c b/src/common/util.c index 391b02f34b..c44fe601e7 100644 --- a/src/common/util.c +++ b/src/common/util.c @@ -1416,7 +1416,10 @@ parse_http_time(const char *date, struct tm *tm) /* First, try RFC1123 or RFC850 format: skip the weekday. */ if ((cp = strchr(date, ','))) { - cp += 2; + ++cp; + if (*cp != ' ') + return -1; + ++cp; if (tor_sscanf(cp, "%2u %3s %4u %2u:%2u:%2u GMT", &tm_mday, month, &tm_year, &tm_hour, &tm_min, &tm_sec) == 6) { diff --git a/src/test/test_util.c b/src/test/test_util.c index 5845d779be..e239326a2d 100644 --- a/src/test/test_util.c +++ b/src/test/test_util.c @@ -101,6 +101,7 @@ test_util_parse_http_time(void *arg) test_eq(-1, parse_http_time("Sunday, 32-Aug-94 00:48:22 GMT", &a_time)); test_eq(-1, parse_http_time("Sunday, 3-Ago-04 00:48:22", &a_time)); test_eq(-1, parse_http_time("Sunday, August the third", &a_time)); + test_eq(-1, parse_http_time("Wednesday,,04 Aug 1994 00:48:22 GMT", &a_time)); test_eq(0, parse_http_time("Wednesday, 04 Aug 1994 00:48:22 GMT", &a_time)); test_eq((time_t)775961302UL, tor_timegm(&a_time)); |