diff options
author | Matt Johnston <matt@ucc.asn.au> | 2011-12-04 05:31:25 +0800 |
---|---|---|
committer | Matt Johnston <matt@ucc.asn.au> | 2011-12-04 05:31:25 +0800 |
commit | 79e50947f2a6d5638c8e24cb6e90eb2e6d1665c4 (patch) | |
tree | 1f92facba7d6354ea1738a8b1f441e54254e6e05 /svr-authpubkeyoptions.c | |
parent | 034d703f415a91ecba4a61ac165b4bb7e173ac37 (diff) | |
download | dropbear-79e50947f2a6d5638c8e24cb6e90eb2e6d1665c4.tar.gz |
- Fix use-after-free if multiple command requests were sent. Move
the original_command into chansess struct since that makes more sense
Diffstat (limited to 'svr-authpubkeyoptions.c')
-rw-r--r-- | svr-authpubkeyoptions.c | 13 |
1 files changed, 7 insertions, 6 deletions
diff --git a/svr-authpubkeyoptions.c b/svr-authpubkeyoptions.c index fd87703..4490b58 100644 --- a/svr-authpubkeyoptions.c +++ b/svr-authpubkeyoptions.c @@ -92,14 +92,15 @@ int svr_pubkey_allows_pty() { * by any 'command' public key option. */ void svr_pubkey_set_forced_command(struct ChanSess *chansess) { if (ses.authstate.pubkey_options) { - ses.authstate.pubkey_options->original_command = chansess->cmd; - if (!chansess->cmd) - { - ses.authstate.pubkey_options->original_command = m_strdup(""); + if (chansess->cmd) { + /* original_command takes ownership */ + chansess->original_command = chansess->cmd; + } else { + chansess->original_command = m_strdup(""); } - chansess->cmd = ses.authstate.pubkey_options->forced_command; + chansess->cmd = m_strdup(ses.authstate.pubkey_options->forced_command); #ifdef LOG_COMMANDS - dropbear_log(LOG_INFO, "Command forced to '%s'", ses.authstate.pubkey_options->original_command); + dropbear_log(LOG_INFO, "Command forced to '%s'", chansess->original_command); #endif } } |