Skip to content

Commit

Permalink
auth/pam: Fix double-free crash
Browse files Browse the repository at this point in the history
conv_func may be called multiple times and should return
a unique pam_response each time.

Closes #272.
  • Loading branch information
foxcpp committed Mar 6, 2022
1 parent 7ee6a39 commit cf94882
Show file tree
Hide file tree
Showing 3 changed files with 54 additions and 28 deletions.
33 changes: 18 additions & 15 deletions cmd/maddy-pam-helper/pam.c
Original file line number Diff line number Diff line change
@@ -1,5 +1,3 @@
//+build libpam

/*
Maddy Mail Server - Composable all-in-one email server.
Copyright © 2019-2022 Max Mazurov <[email protected]>, Maddy Mail Server contributors
Expand All @@ -21,28 +19,33 @@ along with this program. If not, see <https://www.gnu.org/licenses/>.
#define _POSIX_C_SOURCE 200809L
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <security/pam_appl.h>
#include "pam.h"

static int conv_func(int num_msg, const struct pam_message **msg, struct pam_response **resp, void *appdata_ptr) {
*resp = (struct pam_response*)appdata_ptr;
return PAM_SUCCESS;
}

struct error_obj run_pam_auth(const char *username, char *password) {
// PAM frees pam_response for us.
struct pam_response *reply = malloc(sizeof(struct pam_response));
if (reply == NULL) {
struct error_obj ret_val;
ret_val.status = 2;
ret_val.func_name = "malloc";
ret_val.error_msg = "Out of memory";
return ret_val;
return PAM_CONV_ERR;
}
reply->resp = password;

char* password_cpy = malloc(strlen((char*)appdata_ptr)+1);
if (password_cpy == NULL) {
return PAM_CONV_ERR;
}
memcpy(password_cpy, (char*)appdata_ptr, strlen((char*)appdata_ptr)+1);

reply->resp = password_cpy;
reply->resp_retcode = 0;

const struct pam_conv local_conv = { conv_func, reply };
// PAM frees pam_response for us.
*resp = reply;

return PAM_SUCCESS;
}

struct error_obj run_pam_auth(const char *username, char *password) {
const struct pam_conv local_conv = { conv_func, password };
pam_handle_t *local_auth = NULL;
int status = pam_start("maddy", username, &local_conv, &local_auth);
if (status != PAM_SUCCESS) {
Expand Down
18 changes: 18 additions & 0 deletions cmd/maddy-pam-helper/pam.h
Original file line number Diff line number Diff line change
@@ -1,3 +1,21 @@
/*
Maddy Mail Server - Composable all-in-one email server.
Copyright © 2019-2020 Max Mazurov <[email protected]>, Maddy Mail Server contributors
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
*/

#pragma once

struct error_obj {
Expand Down
31 changes: 18 additions & 13 deletions internal/auth/pam/pam.c
Original file line number Diff line number Diff line change
Expand Up @@ -21,28 +21,33 @@ along with this program. If not, see <https://www.gnu.org/licenses/>.
#define _POSIX_C_SOURCE 200809L
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <security/pam_appl.h>
#include "pam.h"

static int conv_func(int num_msg, const struct pam_message **msg, struct pam_response **resp, void *appdata_ptr) {
*resp = (struct pam_response*)appdata_ptr;
return PAM_SUCCESS;
}

struct error_obj run_pam_auth(const char *username, char *password) {
// PAM frees pam_response for us.
struct pam_response *reply = malloc(sizeof(struct pam_response));
if (reply == NULL) {
struct error_obj ret_val;
ret_val.status = 2;
ret_val.func_name = "malloc";
ret_val.error_msg = "Out of memory";
return ret_val;
return PAM_CONV_ERR;
}
reply->resp = password;

char* password_cpy = malloc(strlen((char*)appdata_ptr)+1);
if (password_cpy == NULL) {
return PAM_CONV_ERR;
}
memcpy(password_cpy, (char*)appdata_ptr, strlen((char*)appdata_ptr)+1);

reply->resp = password_cpy;
reply->resp_retcode = 0;

const struct pam_conv local_conv = { conv_func, reply };
// PAM frees pam_response for us.
*resp = reply;

return PAM_SUCCESS;
}

struct error_obj run_pam_auth(const char *username, char *password) {
const struct pam_conv local_conv = { conv_func, password };
pam_handle_t *local_auth = NULL;
int status = pam_start("maddy", username, &local_conv, &local_auth);
if (status != PAM_SUCCESS) {
Expand Down

0 comments on commit cf94882

Please sign in to comment.