Lines 68-73
Link Here
|
68 |
/* header (IN/OUT) pointer to the header structure to fill out */ |
68 |
/* header (IN/OUT) pointer to the header structure to fill out */ |
69 |
/*=========================================================================*/ |
69 |
/*=========================================================================*/ |
70 |
{ |
70 |
{ |
|
|
71 |
if (buffer->end - buffer->start < 2) |
72 |
{ |
73 |
return SLP_ERROR_PARSE_ERROR; |
74 |
} |
71 |
header->version = *(buffer->curpos); |
75 |
header->version = *(buffer->curpos); |
72 |
header->functionid = *(buffer->curpos + 1); |
76 |
header->functionid = *(buffer->curpos + 1); |
73 |
|
77 |
|
Lines 75-80
Link Here
|
75 |
{ |
79 |
{ |
76 |
return SLP_ERROR_VER_NOT_SUPPORTED; |
80 |
return SLP_ERROR_VER_NOT_SUPPORTED; |
77 |
} |
81 |
} |
|
|
82 |
/* check for invalid length 18 bytes is the smallest v2 message*/ |
83 |
if (buffer->end - buffer->start < 18) |
84 |
{ |
85 |
return SLP_ERROR_PARSE_ERROR; |
86 |
} |
78 |
header->length = AsUINT24(buffer->curpos + 2); |
87 |
header->length = AsUINT24(buffer->curpos + 2); |
79 |
header->flags = AsUINT16(buffer->curpos + 5); |
88 |
header->flags = AsUINT16(buffer->curpos + 5); |
80 |
header->encoding = 0; /* not used for SLPv2 */ |
89 |
header->encoding = 0; /* not used for SLPv2 */ |
Lines 89-97
Link Here
|
89 |
return SLP_ERROR_PARSE_ERROR; |
98 |
return SLP_ERROR_PARSE_ERROR; |
90 |
} |
99 |
} |
91 |
|
100 |
|
92 |
/* check for invalid length 18 bytes is the smallest v2 message*/ |
101 |
if(header->length != buffer->end - buffer->start) |
93 |
if(header->length != buffer->end - buffer->start || |
|
|
94 |
header->length < 18) |
95 |
{ |
102 |
{ |
96 |
return SLP_ERROR_PARSE_ERROR; |
103 |
return SLP_ERROR_PARSE_ERROR; |
97 |
} |
104 |
} |
Lines 187-193
Link Here
|
187 |
/* parse out url */ |
194 |
/* parse out url */ |
188 |
urlentry->urllen = AsUINT16(buffer->curpos); |
195 |
urlentry->urllen = AsUINT16(buffer->curpos); |
189 |
buffer->curpos = buffer->curpos + 2; |
196 |
buffer->curpos = buffer->curpos + 2; |
190 |
if(urlentry->urllen > buffer->end - buffer->curpos) |
197 |
if(urlentry->urllen + 1 > buffer->end - buffer->curpos) |
191 |
{ |
198 |
{ |
192 |
return SLP_ERROR_PARSE_ERROR; |
199 |
return SLP_ERROR_PARSE_ERROR; |
193 |
} |
200 |
} |
Lines 235-241
Link Here
|
235 |
/* parse the prlist */ |
242 |
/* parse the prlist */ |
236 |
srvrqst->prlistlen = AsUINT16(buffer->curpos); |
243 |
srvrqst->prlistlen = AsUINT16(buffer->curpos); |
237 |
buffer->curpos = buffer->curpos + 2; |
244 |
buffer->curpos = buffer->curpos + 2; |
238 |
if(srvrqst->prlistlen > buffer->end - buffer->curpos) |
245 |
if(srvrqst->prlistlen + 2 > buffer->end - buffer->curpos) |
239 |
{ |
246 |
{ |
240 |
return SLP_ERROR_PARSE_ERROR; |
247 |
return SLP_ERROR_PARSE_ERROR; |
241 |
} |
248 |
} |
Lines 246-252
Link Here
|
246 |
/* parse the service type */ |
253 |
/* parse the service type */ |
247 |
srvrqst->srvtypelen = AsUINT16(buffer->curpos); |
254 |
srvrqst->srvtypelen = AsUINT16(buffer->curpos); |
248 |
buffer->curpos = buffer->curpos + 2; |
255 |
buffer->curpos = buffer->curpos + 2; |
249 |
if(srvrqst->srvtypelen > buffer->end - buffer->curpos) |
256 |
if(srvrqst->srvtypelen + 2 > buffer->end - buffer->curpos) |
250 |
{ |
257 |
{ |
251 |
return SLP_ERROR_PARSE_ERROR; |
258 |
return SLP_ERROR_PARSE_ERROR; |
252 |
} |
259 |
} |
Lines 257-263
Link Here
|
257 |
/* parse the scope list */ |
264 |
/* parse the scope list */ |
258 |
srvrqst->scopelistlen = AsUINT16(buffer->curpos); |
265 |
srvrqst->scopelistlen = AsUINT16(buffer->curpos); |
259 |
buffer->curpos = buffer->curpos + 2; |
266 |
buffer->curpos = buffer->curpos + 2; |
260 |
if(srvrqst->scopelistlen > buffer->end - buffer->curpos) |
267 |
if(srvrqst->scopelistlen + 2 > buffer->end - buffer->curpos) |
261 |
{ |
268 |
{ |
262 |
return SLP_ERROR_PARSE_ERROR; |
269 |
return SLP_ERROR_PARSE_ERROR; |
263 |
} |
270 |
} |
Lines 269-275
Link Here
|
269 |
srvrqst->predicatever = 2; /* SLPv2 predicate (LDAPv3) */ |
276 |
srvrqst->predicatever = 2; /* SLPv2 predicate (LDAPv3) */ |
270 |
srvrqst->predicatelen = AsUINT16(buffer->curpos); |
277 |
srvrqst->predicatelen = AsUINT16(buffer->curpos); |
271 |
buffer->curpos = buffer->curpos + 2; |
278 |
buffer->curpos = buffer->curpos + 2; |
272 |
if(srvrqst->predicatelen > buffer->end - buffer->curpos) |
279 |
if(srvrqst->predicatelen + 2 > buffer->end - buffer->curpos) |
273 |
{ |
280 |
{ |
274 |
return SLP_ERROR_PARSE_ERROR; |
281 |
return SLP_ERROR_PARSE_ERROR; |
275 |
} |
282 |
} |
Lines 358-367
Link Here
|
358 |
return result; |
365 |
return result; |
359 |
} |
366 |
} |
360 |
|
367 |
|
|
|
368 |
if(buffer->end - buffer->curpos < 2) |
369 |
{ |
370 |
return SLP_ERROR_PARSE_ERROR; |
371 |
} |
361 |
/* parse the service type */ |
372 |
/* parse the service type */ |
362 |
srvreg->srvtypelen = AsUINT16(buffer->curpos); |
373 |
srvreg->srvtypelen = AsUINT16(buffer->curpos); |
363 |
buffer->curpos = buffer->curpos + 2; |
374 |
buffer->curpos = buffer->curpos + 2; |
364 |
if(srvreg->srvtypelen > buffer->end - buffer->curpos) |
375 |
if(srvreg->srvtypelen + 2 > buffer->end - buffer->curpos) |
365 |
{ |
376 |
{ |
366 |
return SLP_ERROR_PARSE_ERROR; |
377 |
return SLP_ERROR_PARSE_ERROR; |
367 |
} |
378 |
} |
Lines 372-378
Link Here
|
372 |
/* parse the scope list */ |
383 |
/* parse the scope list */ |
373 |
srvreg->scopelistlen = AsUINT16(buffer->curpos); |
384 |
srvreg->scopelistlen = AsUINT16(buffer->curpos); |
374 |
buffer->curpos = buffer->curpos + 2; |
385 |
buffer->curpos = buffer->curpos + 2; |
375 |
if(srvreg->scopelistlen > buffer->end - buffer->curpos) |
386 |
if(srvreg->scopelistlen + 2 > buffer->end - buffer->curpos) |
376 |
{ |
387 |
{ |
377 |
return SLP_ERROR_PARSE_ERROR; |
388 |
return SLP_ERROR_PARSE_ERROR; |
378 |
} |
389 |
} |
Lines 383-389
Link Here
|
383 |
/* parse the attribute list*/ |
394 |
/* parse the attribute list*/ |
384 |
srvreg->attrlistlen = AsUINT16(buffer->curpos); |
395 |
srvreg->attrlistlen = AsUINT16(buffer->curpos); |
385 |
buffer->curpos = buffer->curpos + 2; |
396 |
buffer->curpos = buffer->curpos + 2; |
386 |
if(srvreg->attrlistlen > buffer->end - buffer->curpos) |
397 |
if(srvreg->attrlistlen + 1 > buffer->end - buffer->curpos) |
387 |
{ |
398 |
{ |
388 |
return SLP_ERROR_PARSE_ERROR; |
399 |
return SLP_ERROR_PARSE_ERROR; |
389 |
} |
400 |
} |
Lines 447-452
Link Here
|
447 |
} |
458 |
} |
448 |
|
459 |
|
449 |
/* parse the tag list */ |
460 |
/* parse the tag list */ |
|
|
461 |
if(buffer->end - buffer->curpos < 2) |
462 |
{ |
463 |
return SLP_ERROR_PARSE_ERROR; |
464 |
} |
450 |
srvdereg->taglistlen = AsUINT16(buffer->curpos); |
465 |
srvdereg->taglistlen = AsUINT16(buffer->curpos); |
451 |
buffer->curpos = buffer->curpos + 2; |
466 |
buffer->curpos = buffer->curpos + 2; |
452 |
if(srvdereg->taglistlen > buffer->end - buffer->curpos) |
467 |
if(srvdereg->taglistlen > buffer->end - buffer->curpos) |
Lines 482-488
Link Here
|
482 |
/* parse the prlist */ |
497 |
/* parse the prlist */ |
483 |
attrrqst->prlistlen = AsUINT16(buffer->curpos); |
498 |
attrrqst->prlistlen = AsUINT16(buffer->curpos); |
484 |
buffer->curpos = buffer->curpos + 2; |
499 |
buffer->curpos = buffer->curpos + 2; |
485 |
if(attrrqst->prlistlen > buffer->end - buffer->curpos) |
500 |
if(attrrqst->prlistlen + 2 > buffer->end - buffer->curpos) |
486 |
{ |
501 |
{ |
487 |
return SLP_ERROR_PARSE_ERROR; |
502 |
return SLP_ERROR_PARSE_ERROR; |
488 |
} |
503 |
} |
Lines 492-498
Link Here
|
492 |
/* parse the url */ |
507 |
/* parse the url */ |
493 |
attrrqst->urllen = AsUINT16(buffer->curpos); |
508 |
attrrqst->urllen = AsUINT16(buffer->curpos); |
494 |
buffer->curpos = buffer->curpos + 2; |
509 |
buffer->curpos = buffer->curpos + 2; |
495 |
if(attrrqst->urllen > buffer->end - buffer->curpos) |
510 |
if(attrrqst->urllen + 2 > buffer->end - buffer->curpos) |
496 |
{ |
511 |
{ |
497 |
return SLP_ERROR_PARSE_ERROR; |
512 |
return SLP_ERROR_PARSE_ERROR; |
498 |
} |
513 |
} |
Lines 503-509
Link Here
|
503 |
/* parse the scope list */ |
518 |
/* parse the scope list */ |
504 |
attrrqst->scopelistlen = AsUINT16(buffer->curpos); |
519 |
attrrqst->scopelistlen = AsUINT16(buffer->curpos); |
505 |
buffer->curpos = buffer->curpos + 2; |
520 |
buffer->curpos = buffer->curpos + 2; |
506 |
if(attrrqst->scopelistlen > buffer->end - buffer->curpos) |
521 |
if(attrrqst->scopelistlen + 2 > buffer->end - buffer->curpos) |
507 |
{ |
522 |
{ |
508 |
return SLP_ERROR_PARSE_ERROR; |
523 |
return SLP_ERROR_PARSE_ERROR; |
509 |
} |
524 |
} |
Lines 514-520
Link Here
|
514 |
/* parse the taglist string */ |
529 |
/* parse the taglist string */ |
515 |
attrrqst->taglistlen = AsUINT16(buffer->curpos); |
530 |
attrrqst->taglistlen = AsUINT16(buffer->curpos); |
516 |
buffer->curpos = buffer->curpos + 2; |
531 |
buffer->curpos = buffer->curpos + 2; |
517 |
if(attrrqst->taglistlen > buffer->end - buffer->curpos) |
532 |
if(attrrqst->taglistlen + 2 > buffer->end - buffer->curpos) |
518 |
{ |
533 |
{ |
519 |
return SLP_ERROR_PARSE_ERROR; |
534 |
return SLP_ERROR_PARSE_ERROR; |
520 |
} |
535 |
} |
Lines 563-569
Link Here
|
563 |
/* parse out the attrlist */ |
578 |
/* parse out the attrlist */ |
564 |
attrrply->attrlistlen = AsUINT16(buffer->curpos); |
579 |
attrrply->attrlistlen = AsUINT16(buffer->curpos); |
565 |
buffer->curpos = buffer->curpos + 2; |
580 |
buffer->curpos = buffer->curpos + 2; |
566 |
if(attrrply->attrlistlen > buffer->end - buffer->curpos) |
581 |
if(attrrply->attrlistlen + 1 > buffer->end - buffer->curpos) |
567 |
{ |
582 |
{ |
568 |
return SLP_ERROR_PARSE_ERROR; |
583 |
return SLP_ERROR_PARSE_ERROR; |
569 |
} |
584 |
} |
Lines 619-631
Link Here
|
619 |
buffer->curpos = buffer->curpos + 2; |
634 |
buffer->curpos = buffer->curpos + 2; |
620 |
|
635 |
|
621 |
/* parse out the bootstamp */ |
636 |
/* parse out the bootstamp */ |
|
|
637 |
if(buffer->end - buffer->curpos < 6) |
638 |
{ |
639 |
return SLP_ERROR_PARSE_ERROR; |
640 |
} |
622 |
daadvert->bootstamp = AsUINT32(buffer->curpos); |
641 |
daadvert->bootstamp = AsUINT32(buffer->curpos); |
623 |
buffer->curpos = buffer->curpos + 4; |
642 |
buffer->curpos = buffer->curpos + 4; |
624 |
|
643 |
|
625 |
/* parse out the url */ |
644 |
/* parse out the url */ |
626 |
daadvert->urllen = AsUINT16(buffer->curpos); |
645 |
daadvert->urllen = AsUINT16(buffer->curpos); |
627 |
buffer->curpos = buffer->curpos + 2; |
646 |
buffer->curpos = buffer->curpos + 2; |
628 |
if(daadvert->urllen > buffer->end - buffer->curpos) |
647 |
if(daadvert->urllen + 2 > buffer->end - buffer->curpos) |
629 |
{ |
648 |
{ |
630 |
return SLP_ERROR_PARSE_ERROR; |
649 |
return SLP_ERROR_PARSE_ERROR; |
631 |
} |
650 |
} |
Lines 635-641
Link Here
|
635 |
/* parse the scope list */ |
654 |
/* parse the scope list */ |
636 |
daadvert->scopelistlen = AsUINT16(buffer->curpos); |
655 |
daadvert->scopelistlen = AsUINT16(buffer->curpos); |
637 |
buffer->curpos = buffer->curpos + 2; |
656 |
buffer->curpos = buffer->curpos + 2; |
638 |
if(daadvert->scopelistlen > buffer->end - buffer->curpos) |
657 |
if(daadvert->scopelistlen + 2 > buffer->end - buffer->curpos) |
639 |
{ |
658 |
{ |
640 |
return SLP_ERROR_PARSE_ERROR; |
659 |
return SLP_ERROR_PARSE_ERROR; |
641 |
} |
660 |
} |
Lines 645-651
Link Here
|
645 |
/* parse the attr list */ |
664 |
/* parse the attr list */ |
646 |
daadvert->attrlistlen = AsUINT16(buffer->curpos); |
665 |
daadvert->attrlistlen = AsUINT16(buffer->curpos); |
647 |
buffer->curpos = buffer->curpos + 2; |
666 |
buffer->curpos = buffer->curpos + 2; |
648 |
if(daadvert->attrlistlen > buffer->end - buffer->curpos) |
667 |
if(daadvert->attrlistlen + 2 > buffer->end - buffer->curpos) |
649 |
{ |
668 |
{ |
650 |
return SLP_ERROR_PARSE_ERROR; |
669 |
return SLP_ERROR_PARSE_ERROR; |
651 |
} |
670 |
} |
Lines 655-661
Link Here
|
655 |
/* parse the SPI list */ |
674 |
/* parse the SPI list */ |
656 |
daadvert->spilistlen = AsUINT16(buffer->curpos); |
675 |
daadvert->spilistlen = AsUINT16(buffer->curpos); |
657 |
buffer->curpos = buffer->curpos + 2; |
676 |
buffer->curpos = buffer->curpos + 2; |
658 |
if(daadvert->spilistlen > buffer->end - buffer->curpos) |
677 |
if(daadvert->spilistlen + 1 > buffer->end - buffer->curpos) |
659 |
{ |
678 |
{ |
660 |
return SLP_ERROR_PARSE_ERROR; |
679 |
return SLP_ERROR_PARSE_ERROR; |
661 |
} |
680 |
} |
Lines 704-710
Link Here
|
704 |
/* parse out the url */ |
723 |
/* parse out the url */ |
705 |
saadvert->urllen = AsUINT16(buffer->curpos); |
724 |
saadvert->urllen = AsUINT16(buffer->curpos); |
706 |
buffer->curpos = buffer->curpos + 2; |
725 |
buffer->curpos = buffer->curpos + 2; |
707 |
if(saadvert->urllen > buffer->end - buffer->curpos) |
726 |
if(saadvert->urllen + 2 > buffer->end - buffer->curpos) |
708 |
{ |
727 |
{ |
709 |
return SLP_ERROR_PARSE_ERROR; |
728 |
return SLP_ERROR_PARSE_ERROR; |
710 |
} |
729 |
} |
Lines 714-720
Link Here
|
714 |
/* parse the scope list */ |
733 |
/* parse the scope list */ |
715 |
saadvert->scopelistlen = AsUINT16(buffer->curpos); |
734 |
saadvert->scopelistlen = AsUINT16(buffer->curpos); |
716 |
buffer->curpos = buffer->curpos + 2; |
735 |
buffer->curpos = buffer->curpos + 2; |
717 |
if(saadvert->scopelistlen > buffer->end - buffer->curpos) |
736 |
if(saadvert->scopelistlen + 2 > buffer->end - buffer->curpos) |
718 |
{ |
737 |
{ |
719 |
return SLP_ERROR_PARSE_ERROR; |
738 |
return SLP_ERROR_PARSE_ERROR; |
720 |
} |
739 |
} |
Lines 724-730
Link Here
|
724 |
/* parse the attr list */ |
743 |
/* parse the attr list */ |
725 |
saadvert->attrlistlen = AsUINT16(buffer->curpos); |
744 |
saadvert->attrlistlen = AsUINT16(buffer->curpos); |
726 |
buffer->curpos = buffer->curpos + 2; |
745 |
buffer->curpos = buffer->curpos + 2; |
727 |
if(saadvert->attrlistlen > buffer->end - buffer->curpos) |
746 |
if(saadvert->attrlistlen + 1 > buffer->end - buffer->curpos) |
728 |
{ |
747 |
{ |
729 |
return SLP_ERROR_PARSE_ERROR; |
748 |
return SLP_ERROR_PARSE_ERROR; |
730 |
} |
749 |
} |
Lines 769-775
Link Here
|
769 |
/* parse the prlist */ |
788 |
/* parse the prlist */ |
770 |
srvtyperqst->prlistlen = AsUINT16(buffer->curpos); |
789 |
srvtyperqst->prlistlen = AsUINT16(buffer->curpos); |
771 |
buffer->curpos += 2; |
790 |
buffer->curpos += 2; |
772 |
if(srvtyperqst->prlistlen > buffer->end - buffer->curpos) |
791 |
if(srvtyperqst->prlistlen + 2 > buffer->end - buffer->curpos) |
773 |
{ |
792 |
{ |
774 |
return SLP_ERROR_PARSE_ERROR; |
793 |
return SLP_ERROR_PARSE_ERROR; |
775 |
} |
794 |
} |
Lines 794-799
Link Here
|
794 |
} |
813 |
} |
795 |
|
814 |
|
796 |
/* parse the scope list */ |
815 |
/* parse the scope list */ |
|
|
816 |
if(buffer->end - buffer->curpos < 2) |
817 |
{ |
818 |
return SLP_ERROR_PARSE_ERROR; |
819 |
} |
797 |
srvtyperqst->scopelistlen = AsUINT16(buffer->curpos); |
820 |
srvtyperqst->scopelistlen = AsUINT16(buffer->curpos); |
798 |
buffer->curpos += 2; |
821 |
buffer->curpos += 2; |
799 |
if(srvtyperqst->scopelistlen > buffer->end - buffer->curpos) |
822 |
if(srvtyperqst->scopelistlen > buffer->end - buffer->curpos) |