From 539bbf8653e0117dea139015b4b71be768e3f3d7 Mon Sep 17 00:00:00 2001 From: Jeremy Allison Date: Tue, 9 Feb 2010 14:48:15 -0800 Subject: [PATCH] Second part of fix for bug 7063 - Samba 3.4.5 on ubuntu 8.04 64 bit - Core dumps. Ensure we have no naked memcpy calls. This isn't a crash bug (it's already checked in the data_blob_talloc_zero() above, but I want to get into the pattern of having all memcpy's covered by safety checks. Jeremy. --- source3/rpc_server/srv_spoolss_nt.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/source3/rpc_server/srv_spoolss_nt.c b/source3/rpc_server/srv_spoolss_nt.c index e2e523d0de4..33d47df33aa 100644 --- a/source3/rpc_server/srv_spoolss_nt.c +++ b/source3/rpc_server/srv_spoolss_nt.c @@ -9455,7 +9455,10 @@ WERROR _spoolss_XcvData(pipes_struct *p, *r->out.status_code = 0; - memcpy(r->out.out_data, out_data.data, out_data.length); + if (r->out.out_data && r->in.out_data_size && out_data.length) { + memcpy(r->out.out_data, out_data.data, + MIN(r->in.out_data_size, out_data.length)); + } return WERR_OK; } -- 2.34.1