|
 |
398fc5 |
From c6f2737747cbb70adfdd1a77412b669838f9c419 Mon Sep 17 00:00:00 2001
|
|
 |
398fc5 |
From: Rob Crittenden <rcritten@redhat.com>
|
|
 |
398fc5 |
Date: Mon, 2 Dec 2019 15:08:54 -0500
|
|
 |
398fc5 |
Subject: [PATCH] Fix use-after-free issue
|
|
 |
398fc5 |
|
|
 |
398fc5 |
The basedn value was freed after the first search but a second
|
|
 |
398fc5 |
one could be initiated.
|
|
 |
398fc5 |
---
|
|
 |
398fc5 |
src/ipa.c | 2 +-
|
|
 |
398fc5 |
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
 |
398fc5 |
|
|
 |
398fc5 |
diff --git a/src/ipa.c b/src/ipa.c
|
|
 |
398fc5 |
index 40a4b52c..41ca9081 100644
|
|
 |
398fc5 |
--- a/src/ipa.c
|
|
 |
398fc5 |
+++ b/src/ipa.c
|
|
 |
398fc5 |
@@ -540,7 +540,6 @@ fetch_roots(const char *server, int ldap_uri_cmd, const char *ldap_uri,
|
|
 |
398fc5 |
/* Now look up the root certificates for the domain. */
|
|
 |
398fc5 |
snprintf(lfilter, sizeof(lfilter), "(%s=*)", lattrs[0]);
|
|
 |
398fc5 |
snprintf(ldn, sizeof(ldn), "%s,%s", relativedn, basedn);
|
|
 |
398fc5 |
- free(basedn);
|
|
 |
398fc5 |
rc = ldap_search_ext_s(ld, ldn, LDAP_SCOPE_SUBTREE,
|
|
 |
398fc5 |
lfilter, lattrs, 0, NULL, NULL, NULL,
|
|
 |
398fc5 |
LDAP_NO_LIMIT, &lresult);
|
|
 |
398fc5 |
@@ -551,6 +550,7 @@ fetch_roots(const char *server, int ldap_uri_cmd, const char *ldap_uri,
|
|
 |
398fc5 |
lfilter, lattrs, 0, NULL, NULL, NULL,
|
|
 |
398fc5 |
LDAP_NO_LIMIT, &lresult);
|
|
 |
398fc5 |
}
|
|
 |
398fc5 |
+ free(basedn);
|
|
 |
398fc5 |
if (rc != LDAP_SUCCESS) {
|
|
 |
398fc5 |
fprintf(stderr, "Error searching '%s': %s.\n",
|
|
 |
398fc5 |
ldn, ldap_err2string(rc));
|
|
 |
398fc5 |
--
|
|
 |
398fc5 |
2.21.0
|
|
 |
398fc5 |
|