augment simple strtoll() which allowed number to begin with '+' This is not exploitable for HTTP Request Smuggling since lighttpd mod_proxy sends "Connection: close" to backends, and other CGI-based backends reconstitute CONTENT_LENGTH in the environment without '+'. (thx Amit Klein, Safebreach)personal/stbuehler/ci-build
parent
acff179322
commit
6876c16be0
Loading…
Reference in new issue