s3: Fix an uninitialized variable read
authorVolker Lendecke <vl@samba.org>
Sun, 14 Mar 2010 20:18:34 +0000 (21:18 +0100)
committerJeremy Allison <jra@samba.org>
Mon, 15 Mar 2010 23:01:48 +0000 (16:01 -0700)
Found by Laurent Gaffie <laurent.gaffie@gmail.com>

Thanks for that,

Volker

source3/smbd/sesssetup.c

index cad2dd33b81af41b958b7b26cf6de69acaa0f57f..8c0317ae9eb28afd1e8b57eab87a4f6752343f5f 100644 (file)
@@ -1214,7 +1214,7 @@ static void reply_sesssetup_and_X_spnego(struct smb_request *req)
        file_save("negotiate.dat", blob1.data, blob1.length);
 #endif
 
-       p2 = (char *)req->buf + data_blob_len;
+       p2 = (char *)req->buf + blob1.length;
 
        p2 += srvstr_pull_req_talloc(talloc_tos(), req, &tmp, p2,
                                     STR_TERMINATE);