diff options
author | Stefan Metzmacher <metze@samba.org> | 2011-09-06 14:01:43 +0200 |
---|---|---|
committer | Karolin Seeger <kseeger@samba.org> | 2011-10-12 20:59:36 +0200 |
commit | 08bcf626afa38bd783ce3789a2c89749dd98c651 (patch) | |
tree | a6f3a4da14998959e447c33443c395a103772ca2 | |
parent | ee9ee58076acb98d449712f239888038bfb99bc1 (diff) | |
download | samba-08bcf626afa38bd783ce3789a2c89749dd98c651.tar.gz samba-08bcf626afa38bd783ce3789a2c89749dd98c651.tar.xz samba-08bcf626afa38bd783ce3789a2c89749dd98c651.zip |
s3:smb2_server: use smbd_smb2_request_verify_sizes() in smb2_setinfo.c
metze
(cherry picked from commit 3643a05ba63ac5d8466dc8391b5d05efeedb5ac4)
(cherry picked from commit 56b765a8663f59d247f970af8273ba749f094cae)
-rw-r--r-- | source3/smbd/smb2_setinfo.c | 18 |
1 files changed, 5 insertions, 13 deletions
diff --git a/source3/smbd/smb2_setinfo.c b/source3/smbd/smb2_setinfo.c index 96b44aaf774..2d39f11bb55 100644 --- a/source3/smbd/smb2_setinfo.c +++ b/source3/smbd/smb2_setinfo.c @@ -39,11 +39,9 @@ static NTSTATUS smbd_smb2_setinfo_recv(struct tevent_req *req); static void smbd_smb2_request_setinfo_done(struct tevent_req *subreq); NTSTATUS smbd_smb2_request_process_setinfo(struct smbd_smb2_request *req) { - const uint8_t *inhdr; + NTSTATUS status; const uint8_t *inbody; int i = req->current_idx; - size_t expected_body_size = 0x21; - size_t body_size; uint8_t in_info_type; uint8_t in_file_info_class; uint16_t in_input_buffer_offset; @@ -54,18 +52,12 @@ NTSTATUS smbd_smb2_request_process_setinfo(struct smbd_smb2_request *req) uint64_t in_file_id_volatile; struct tevent_req *subreq; - inhdr = (const uint8_t *)req->in.vector[i+0].iov_base; - if (req->in.vector[i+1].iov_len != (expected_body_size & 0xFFFFFFFE)) { - return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER); + status = smbd_smb2_request_verify_sizes(req, 0x21); + if (!NT_STATUS_IS_OK(status)) { + return smbd_smb2_request_error(req, status); } - inbody = (const uint8_t *)req->in.vector[i+1].iov_base; - body_size = SVAL(inbody, 0x00); - if (body_size != expected_body_size) { - return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER); - } - in_info_type = CVAL(inbody, 0x02); in_file_info_class = CVAL(inbody, 0x03); in_input_buffer_length = IVAL(inbody, 0x04); @@ -78,7 +70,7 @@ NTSTATUS smbd_smb2_request_process_setinfo(struct smbd_smb2_request *req) if (in_input_buffer_offset == 0 && in_input_buffer_length == 0) { /* This is ok */ } else if (in_input_buffer_offset != - (SMB2_HDR_BODY + (body_size & 0xFFFFFFFE))) { + (SMB2_HDR_BODY + req->in.vector[i+1].iov_len)) { return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER); } |