summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorStefan Metzmacher <metze@samba.org>2011-09-06 14:01:43 +0200
committerKarolin Seeger <kseeger@samba.org>2011-10-12 20:58:56 +0200
commitc9a09ca982f4fc079a027cf62ad61c3c83adec53 (patch)
tree89e8bf172145fa15e556410e5e8ef4c0025ce398
parent179cc11a48d86f4cf8752dd8163721ca4b168b4b (diff)
downloadsamba-c9a09ca982f4fc079a027cf62ad61c3c83adec53.tar.gz
samba-c9a09ca982f4fc079a027cf62ad61c3c83adec53.tar.xz
samba-c9a09ca982f4fc079a027cf62ad61c3c83adec53.zip
s3:smb2_server: use smbd_smb2_request_verify_sizes() in smb2_create.c
metze (cherry picked from commit 251815bfd395398857cb60c0b89710ddce7ab19f) (cherry picked from commit 4e4817930955228923f04540404786ff88ad14f8)
-rw-r--r--source3/smbd/smb2_create.c15
1 files changed, 4 insertions, 11 deletions
diff --git a/source3/smbd/smb2_create.c b/source3/smbd/smb2_create.c
index 5316100e60a..c53e49122fe 100644
--- a/source3/smbd/smb2_create.c
+++ b/source3/smbd/smb2_create.c
@@ -100,8 +100,6 @@ NTSTATUS smbd_smb2_request_process_create(struct smbd_smb2_request *smb2req)
{
const uint8_t *inbody;
int i = smb2req->current_idx;
- size_t expected_body_size = 0x39;
- size_t body_size;
uint8_t in_oplock_level;
uint32_t in_impersonation_level;
uint32_t in_desired_access;
@@ -127,17 +125,12 @@ NTSTATUS smbd_smb2_request_process_create(struct smbd_smb2_request *smb2req)
bool ok;
struct tevent_req *tsubreq;
- if (smb2req->in.vector[i+1].iov_len != (expected_body_size & 0xFFFFFFFE)) {
- return smbd_smb2_request_error(smb2req, NT_STATUS_INVALID_PARAMETER);
+ status = smbd_smb2_request_verify_sizes(smb2req, 0x39);
+ if (!NT_STATUS_IS_OK(status)) {
+ return smbd_smb2_request_error(smb2req, status);
}
-
inbody = (const uint8_t *)smb2req->in.vector[i+1].iov_base;
- body_size = SVAL(inbody, 0x00);
- if (body_size != expected_body_size) {
- return smbd_smb2_request_error(smb2req, NT_STATUS_INVALID_PARAMETER);
- }
-
in_oplock_level = CVAL(inbody, 0x03);
in_impersonation_level = IVAL(inbody, 0x04);
in_desired_access = IVAL(inbody, 0x18);
@@ -158,7 +151,7 @@ NTSTATUS smbd_smb2_request_process_create(struct smbd_smb2_request *smb2req)
* overlap
*/
- dyn_offset = SMB2_HDR_BODY + (body_size & 0xFFFFFFFE);
+ dyn_offset = SMB2_HDR_BODY + smb2req->in.vector[i+1].iov_len;
if (in_name_offset == 0 && in_name_length == 0) {
/* This is ok */