From 7c542406b192cd72c40778850d92771974d6466c Mon Sep 17 00:00:00 2001 From: Andrew Tridgell Date: Fri, 18 Sep 2009 22:58:03 -0700 Subject: s4-pipes: convert pipe names to lowercase and validate clients may provide arbitrary names, but we only want lowercase alnum names --- source4/ntvfs/ipc/vfs_ipc.c | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) (limited to 'source4/ntvfs') diff --git a/source4/ntvfs/ipc/vfs_ipc.c b/source4/ntvfs/ipc/vfs_ipc.c index 0cd909e351..3a27b8d7b0 100644 --- a/source4/ntvfs/ipc/vfs_ipc.c +++ b/source4/ntvfs/ipc/vfs_ipc.c @@ -39,6 +39,7 @@ #include "auth/credentials/credentials.h" #include "auth/credentials/credentials_krb5.h" #include +#include "system/locale.h" /* this is the private structure used to keep the state of an open ipc$ connection. It needs to keep information about all open @@ -221,6 +222,18 @@ struct ipc_open_state { static void ipc_open_done(struct tevent_req *subreq); +/* + check the pipename is valid + */ +static NTSTATUS validate_pipename(const char *name) +{ + while (*name) { + if (!isalnum(*name)) return NT_STATUS_INVALID_PARAMETER; + name++; + } + return NT_STATUS_OK; +} + /* open a file - used for MSRPC pipes */ @@ -275,6 +288,12 @@ static NTSTATUS ipc_open(struct ntvfs_module_context *ntvfs, while (fname[0] == '\\') fname++; + /* check for valid characters in name */ + fname = strlower_talloc(p, fname); + + status = validate_pipename(fname); + NT_STATUS_NOT_OK_RETURN(status); + p->pipe_name = talloc_asprintf(p, "\\pipe\\%s", fname); NT_STATUS_HAVE_NO_MEMORY(p->pipe_name); -- cgit