summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorStefan Metzmacher <metze@samba.org>2011-09-06 14:01:43 +0200
committerKarolin Seeger <kseeger@samba.org>2011-10-12 20:58:41 +0200
commitb58c986377a9b1d721fa73cb976d8e6f721512f4 (patch)
tree399e2bf6dfb20a067ff0b0acd217878e14799c3d
parent6b1627866ff294946adb720cbf7e9faab79192cc (diff)
downloadsamba-b58c986377a9b1d721fa73cb976d8e6f721512f4.tar.gz
samba-b58c986377a9b1d721fa73cb976d8e6f721512f4.tar.xz
samba-b58c986377a9b1d721fa73cb976d8e6f721512f4.zip
s3:smb2_server: use smbd_smb2_request_verify_sizes() in smb2_sesssetup.c
metze (cherry picked from commit d280d9f945be2d658694c6d4503822e99dc953b5) (cherry picked from commit fd01ec18dc84b4d632bf9384705d72f2a970cf65)
-rw-r--r--source3/smbd/smb2_sesssetup.c35
1 files changed, 9 insertions, 26 deletions
diff --git a/source3/smbd/smb2_sesssetup.c b/source3/smbd/smb2_sesssetup.c
index 49aabdb7a7a..53f9d104a6e 100644
--- a/source3/smbd/smb2_sesssetup.c
+++ b/source3/smbd/smb2_sesssetup.c
@@ -47,8 +47,6 @@ NTSTATUS smbd_smb2_request_process_sesssetup(struct smbd_smb2_request *smb2req)
uint8_t *outhdr;
DATA_BLOB outbody;
DATA_BLOB outdyn;
- size_t expected_body_size = 0x19;
- size_t body_size;
uint64_t in_session_id;
uint8_t in_security_mode;
uint16_t in_security_offset;
@@ -60,23 +58,17 @@ NTSTATUS smbd_smb2_request_process_sesssetup(struct smbd_smb2_request *smb2req)
DATA_BLOB out_security_buffer = data_blob_null;
NTSTATUS status;
- inhdr = (const uint8_t *)smb2req->in.vector[i+0].iov_base;
-
- if (smb2req->in.vector[i+1].iov_len != (expected_body_size & 0xFFFFFFFE)) {
- return smbd_smb2_request_error(smb2req, NT_STATUS_INVALID_PARAMETER);
+ status = smbd_smb2_request_verify_sizes(smb2req, 0x19);
+ if (!NT_STATUS_IS_OK(status)) {
+ return smbd_smb2_request_error(smb2req, status);
}
-
+ inhdr = (const uint8_t *)smb2req->in.vector[i+0].iov_base;
inbody = (const uint8_t *)smb2req->in.vector[i+1].iov_base;
- body_size = SVAL(inbody, 0x00);
- if (body_size != expected_body_size) {
- return smbd_smb2_request_error(smb2req, NT_STATUS_INVALID_PARAMETER);
- }
-
in_security_offset = SVAL(inbody, 0x0C);
in_security_length = SVAL(inbody, 0x0E);
- if (in_security_offset != (SMB2_HDR_BODY + (body_size & 0xFFFFFFFE))) {
+ if (in_security_offset != (SMB2_HDR_BODY + smb2req->in.vector[i+1].iov_len)) {
return smbd_smb2_request_error(smb2req, NT_STATUS_INVALID_PARAMETER);
}
@@ -878,21 +870,12 @@ NTSTATUS smbd_smb2_request_check_session(struct smbd_smb2_request *req)
NTSTATUS smbd_smb2_request_process_logoff(struct smbd_smb2_request *req)
{
- const uint8_t *inbody;
- int i = req->current_idx;
+ NTSTATUS status;
DATA_BLOB outbody;
- size_t expected_body_size = 0x04;
- size_t body_size;
- if (req->in.vector[i+1].iov_len != (expected_body_size & 0xFFFFFFFE)) {
- return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
- }
-
- inbody = (const uint8_t *)req->in.vector[i+1].iov_base;
-
- body_size = SVAL(inbody, 0x00);
- if (body_size != expected_body_size) {
- return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
+ status = smbd_smb2_request_verify_sizes(req, 0x04);
+ if (!NT_STATUS_IS_OK(status)) {
+ return smbd_smb2_request_error(req, status);
}
/*