mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
ParseHttpHeader() used strchr(buffer, ' ') unconditionally as endptr, even though the parser explicitly supports HTTP/0.9-style requests with no trailing space/version (type = SIMPLE). A request line like "GET /" with no space made strchr return null, and nullptr - buffer truncated to a garbage length driving new[]/memcpy. Falls back to the end of the line when no space is found, and clamps param_length to avoid a similar issue when '?' appears after the (missing) space. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY