Nginx security advisory (CVE-2013-2028)
mailman.nginx.org
mailman.nginx.org
Found with:
git log --full-diff --reverse release-1.3.8.. -p src/http/ngx_http_parse.cAlso, are you sure this change introduces the flaw? It looks like it could have been there before the refactor, as well.
https://github.com/git-mirror/nginx/commit/7c7ad803a13d5f73b...
That's a pretty big statement right there.
You are just saying that C is not clean. (IMHO) nginx code-base is doing a really good job dealing with micro-optimization.
>code looks like if it uses trillions of mutable state
Actually, that's a very good approach. e.g. : nginx parser get optimized out as a big jump table (http://en.wikipedia.org/wiki/Branch_table)
* Has functional change + introduces bugs
* No functional changes + introduces bugs
* Has functional changes + doesn't introduce bugs
* No functional changes + doesn't introduce bugs
Also I haven't seen too many commit that say "this introduces 5 new accidental bugs into the system". Just saying, not sure what ou are criticizing hereI'm a big Nginx fan, but I think it's good by just sheer force of will... if you had like 10 people working on it it would probably fall apart. Something sqlite at least has extensive automated tests, which makes me much more confident about its quality.
#if (NGX_HAVE_LITTLE_ENDIAN && NGX_HAVE_NONALIGNED)
#define ngx_str3Ocmp(m, c0, c1, c2, c3). \
*(uint32_t *) m == ((c3 << 24) | (c2 << 16) | (c1 << 8) | c0)
#else /* !(NGX_HAVE_LITTLE_ENDIAN && NGX_HAVE_NONALIGNED) */
#define ngx_str3Ocmp(m, c0, c1, c2, c3) \
m[0] == c0 && m[2] == c2 && m[3] == c3I guess c1 is included in the first case because it's faster to compare the whole 32-bit word than mask out the known byte (and since c0, c1, c2 and c3 are compile time constants, the whole right-hand-side of the comparison will be optimized by constant folding anyway).
(It's ridiculous micro-optimization in my opinion, but at least it is correct, and it is limited to a single file.)
In the first case, comparing 2 integer (4x 8bit) is faster than omitting one byte.
That's is, using ngx_str3Ocmp with c1 != 'O' would be a usage error.
Edit: sltkr, sorry didn't see your reply.
But very few regex libraries are that "good", because it's a combination of extreme speed with very low flexibility (DFA has exponential state explosion in worst cases compared to equivalent NFA, and isn't able to deal with e.g. backreferences). The vast majority of good regex libraries will be an order of magnitude slower. Average regex libraries included in most language distributions will be slower again.
The chief exception is compiler lexer generators like lex and flex. They produce code very similar to the state machine linked. And that's probably the most common place to see this kind of thing.
Encoding the state of the machine implicitly as the program counter, rather than an explicit state variable, often results in more readable code and is the more usual way to do it when writing it by hand. It also saves a register, important on some architectures. But the technique has slightly more limited expressiveness owing to needing to stick with structured programming constructs.
I am on Ubuntu 12.04.2 LTS, I had use "add-apt-repository ppa:nginx/development" to get nginx/1.3.12, how do I get in to the latest release?
Wiki says:
Stable release 1.4.0 / 24 April 2013
Preview release 1.3.16 / 16 April 2013
How do I get into the latest stable bandwagon?
deb http://nginx.org/packages/ubuntu/ precise nginx
deb-src http://nginx.org/packages/ubuntu/ precise nginx
Those are updated very quickly. I haven't timed it but I'm yet to see an advisory before an update is available.[1] http://wiki.nginx.org/Install#Official_Debian.2FUbuntu_packa...
It seems I'm stuck with 1.2.6 for the time being.
I had to install this public key from ubuntu server:
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys ABF5BD827BD9BF62
Had to remove nginx-full and nginx-common.
Then install nginx: apt-get install nginx
Even though I told the installer to keep the default config (which it did) but over-written /etc/nginx/conf.d/default.conf The only change I had to make was port number, since I am using varnish changed my port to 8080 for nginx. Restarted nginx.
nginx version: nginx/1.4.1
Thanks for the help!I just wish it had a make test
Ubuntu 12.04.02 LTS uses Version: 1.1.19-1.
It's pointless to check for such a signed integer overflow after it happened.
+ if (ctx->size < 0 || ctx->length < 0) {
+ goto invalid;
+ }
+
I don't know C/C++ but I was under the impression nobody used goto? Is there anything good/bad about using it?If you have a better way to express the control flow you should use it instead though.
If you are an expert programmer, you can use it in some parts where efficiency is important. Finite State Machine implementations are a common use.
Meaning, the vulnerable versions were likely not out long.