Registry server "reg_ldb_unpack_value": Let "data" pointer be NULL
authorMatthias Dieter Wallnöfer <mwallnoefer@yahoo.de>
Mon, 15 Sep 2008 13:13:25 +0000 (15:13 +0200)
committerJelmer Vernooij <jelmer@samba.org>
Tue, 21 Oct 2008 12:40:41 +0000 (14:40 +0200)
Prevent segfaults in some client applications (e.g. regdiff)

source4/lib/registry/ldb.c

index be844d75d538a1fc57f4ae6e9c7a6fa2d6ec81eb..d15fdb3457f5fcff0912d5175f18504812d14666 100644 (file)
@@ -54,35 +54,39 @@ static void reg_ldb_unpack_value(TALLOC_CTX *mem_ctx,
        value_type = ldb_msg_find_attr_as_uint(msg, "type", 0);
        if (type != NULL)
                *type = value_type; 
        value_type = ldb_msg_find_attr_as_uint(msg, "type", 0);
        if (type != NULL)
                *type = value_type; 
-       val = ldb_msg_find_ldb_val(msg, "data");
 
 
-       switch (value_type)
-       {
-       case REG_SZ:
-       case REG_EXPAND_SZ:
-               data->length = convert_string_talloc(mem_ctx, iconv_convenience, CH_UNIX, CH_UTF16,
+       if (data != NULL) {
+               val = ldb_msg_find_ldb_val(msg, "data");
+
+               switch (value_type)
+               {
+               case REG_SZ:
+               case REG_EXPAND_SZ:
+                       data->length = convert_string_talloc(mem_ctx,
+                               iconv_convenience, CH_UNIX, CH_UTF16,
                                                     val->data, val->length,
                                                     (void **)&data->data);
                                                     val->data, val->length,
                                                     (void **)&data->data);
-               break;
+                       break;
 
 
-       case REG_BINARY:
-               if (val)
-                       *data = strhex_to_data_blob((char *)val->data);
-               else {
-                       data->data = NULL;
-                       data->length = 0;
-               }
-               break;
+               case REG_BINARY:
+                       if (val != NULL)
+                               *data = strhex_to_data_blob((char *)val->data);
+                       else {
+                               data->data = NULL;
+                               data->length = 0;
+                       }
+                       break;
 
 
-       case REG_DWORD: {
-               uint32_t tmp = strtoul((char *)val->data, NULL, 0);
-               *data = data_blob_talloc(mem_ctx, &tmp, 4);
-               }
-               break;
+               case REG_DWORD: {
+                       uint32_t tmp = strtoul((char *)val->data, NULL, 0);
+                       *data = data_blob_talloc(mem_ctx, &tmp, 4);
+                       }
+                       break;
 
 
-       default:
-               *data = data_blob_talloc(mem_ctx, val->data, val->length);
-               break;
+               default:
+                       *data = data_blob_talloc(mem_ctx, val->data, val->length);
+                       break;
+               }
        }
 }
 
        }
 }