Skip to content

Commit

Permalink
Fixed regex captures handling without PCRE.
Browse files Browse the repository at this point in the history
If PCRE is disabled, captures were treated as normal variables in
ngx_http_script_compile(), while code calculating flushes array length in
ngx_http_compile_complex_value() did not account captures as variables.
This could lead to write outside of the array boundary when setting
last element to -1.

Found with AddressSanitizer.
  • Loading branch information
vlhomutov committed Jul 6, 2016
1 parent 74305af commit 161fcf4
Show file tree
Hide file tree
Showing 2 changed files with 16 additions and 12 deletions.
14 changes: 8 additions & 6 deletions src/http/ngx_http_script.c
Original file line number Diff line number Diff line change
Expand Up @@ -350,11 +350,9 @@ ngx_http_script_compile(ngx_http_script_compile_t *sc)
goto invalid_variable;
}

#if (NGX_PCRE)
{
ngx_uint_t n;

if (sc->source->data[i] >= '1' && sc->source->data[i] <= '9') {
#if (NGX_PCRE)
ngx_uint_t n;

n = sc->source->data[i] - '0';

Expand All @@ -371,9 +369,13 @@ ngx_http_script_compile(ngx_http_script_compile_t *sc)
i++;

continue;
}
}
#else
ngx_conf_log_error(NGX_LOG_EMERG, sc->cf, 0,
"using variable \"$%c\" requires "
"PCRE library", sc->source->data[i]);
return NGX_ERROR;
#endif
}

if (sc->source->data[i] == '{') {
bracket = 1;
Expand Down
14 changes: 8 additions & 6 deletions src/stream/ngx_stream_script.c
Original file line number Diff line number Diff line change
Expand Up @@ -282,11 +282,9 @@ ngx_stream_script_compile(ngx_stream_script_compile_t *sc)
goto invalid_variable;
}

#if (NGX_PCRE)
{
ngx_uint_t n;

if (sc->source->data[i] >= '1' && sc->source->data[i] <= '9') {
#if (NGX_PCRE)
ngx_uint_t n;

n = sc->source->data[i] - '0';

Expand All @@ -297,9 +295,13 @@ ngx_stream_script_compile(ngx_stream_script_compile_t *sc)
i++;

continue;
}
}
#else
ngx_conf_log_error(NGX_LOG_EMERG, sc->cf, 0,
"using variable \"$%c\" requires "
"PCRE library", sc->source->data[i]);
return NGX_ERROR;
#endif
}

if (sc->source->data[i] == '{') {
bracket = 1;
Expand Down

0 comments on commit 161fcf4

Please sign in to comment.