Re: Bug: RFC 7230 Section 3.3.3 violation in httpd header parsing enables TE.CL Request Smuggling
Ben Kallus <[email protected]>
| Newsgroups | gmane.os.openbsd.bugs |
|---|---|
| Message-ID | <CAB6pCSa9pkUaTjJFhJrZNx5je2EOtz=X9P62S7rUkE11R=fR1w@mail.gmail.com> |
> security impact of this is minimal. I'm inclined to agree. Anyone processing POSTs with httpd is probably doing so with fastcgi anyway, which is currently (and has always been) broken. I therefore think this likely impacts 0 users. -Ben