From: Philippe Antoine Date: Thu, 26 Jan 2023 08:28:46 +0000 (+0100) Subject: http: complete multipart until request.body-limit X-Git-Tag: suricata-7.0.0-rc2~475 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=578f328e06b3e03f3bdbbf852b5d121e20849b8b;p=thirdparty%2Fsuricata.git http: complete multipart until request.body-limit In the case we are truncating a multipart file because of reaching request.body-limit, we used to not consume the whole buffer, but keep expected_boundary_len bytes in case a new boundary begins in these bytes. Even if we cannot check the complete boundary, we can still check the first bytes, as will be done in the rust version. Ticket: #5952 --- diff --git a/src/app-layer-htp.c b/src/app-layer-htp.c index ee4295cf72..7855fb806d 100644 --- a/src/app-layer-htp.c +++ b/src/app-layer-htp.c @@ -1446,6 +1446,16 @@ static int HtpRequestBodyHandleMultipart(HtpState *hstate, HtpTxUserData *htud, if (chunks_buffer_len > expected_boundary_end_len) { const uint8_t *filedata = chunks_buffer; uint32_t filedata_len = chunks_buffer_len - expected_boundary_len; + for (; filedata_len < chunks_buffer_len; filedata_len++) { + // take as much as we can until the beginning of a new line + if (chunks_buffer[filedata_len] == '\r') { + if (filedata_len + 1 == expected_boundary_len || + chunks_buffer[filedata_len + 1] == '\n') { + break; + } + } + } + #ifdef PRINT printf("FILEDATA (part) START: \n"); PrintRawDataFp(stdout, filedata, filedata_len);