Commit 5778c1261d for openssl.org
commit 5778c1261dc1b39d9758a33a0dd1c3035bad470d
Author: Bob Beck <beck@openssl.org>
Date: Fri Sep 11 20:53:10 2026 -0600
Build the proxy authorization string with asprintf
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Andrew Dinh <andrewd@openssl.org>
Merge-date: Fri Oct 2 07:18:24 2026
Merged-from: https://github.com/openssl/openssl/pull/31550
diff --git a/crypto/http/http_client.c b/crypto/http/http_client.c
index db0aaf6d8b..6cca340923 100644
--- a/crypto/http/http_client.c
+++ b/crypto/http/http_client.c
@@ -23,6 +23,7 @@
#include <openssl/trace.h>
#include "internal/sockets.h"
#include "internal/common.h" /* for ossl_assert() */
+#include "internal/cryptlib.h" /* for ossl_asprintf() */
#define HTTP_PREFIX "HTTP/"
#define HTTP_VERSION_PATT "1." /* allow 1.x */
@@ -1500,25 +1501,19 @@ int OSSL_HTTP_proxy_connect(BIO *bio, const char *server, const char *port,
/* Support for basic (base64) proxy authentication */
if (proxyuser != NULL) {
- size_t len = strlen(proxyuser) + 1;
- char *proxyauth, *proxyauthenc = NULL;
+ char *proxyauth = NULL, *proxyauthenc = NULL;
+ int len;
- if (proxypass != NULL)
- len += strlen(proxypass);
- proxyauth = OPENSSL_malloc(len + 1);
- if (proxyauth == NULL)
+ len = ossl_asprintf(&proxyauth, "%s:%s", proxyuser,
+ proxypass != NULL ? proxypass : "");
+ if (len < 0)
goto end;
- if (snprintf(proxyauth, len + 1, "%s:%s", proxyuser,
- proxypass != NULL ? proxypass : "")
- != (int)len)
- goto proxy_end;
- proxyauthenc = base64encode(proxyauth, len);
+ proxyauthenc = base64encode(proxyauth, (size_t)len);
if (proxyauthenc != NULL) {
BIO_printf(fbio, "Proxy-Authorization: Basic %s\r\n", proxyauthenc);
OPENSSL_clear_free(proxyauthenc, strlen(proxyauthenc));
}
- proxy_end:
- OPENSSL_clear_free(proxyauth, len);
+ OPENSSL_clear_free(proxyauth, (size_t)len);
if (proxyauthenc == NULL)
goto end;
}