miniupnpd/pcpserver.c: Added checks for third-party allowed for it to be used.

If allowed, checking it against source address,
with inverse logic from that of non-thirdparty case.
This commit is contained in:
Markus Stenberg 2014-05-03 08:54:13 +03:00 committed by Thomas Bernard
parent 5e5a9d39eb
commit d058fd3f36
1 changed files with 23 additions and 7 deletions

View File

@ -1049,13 +1049,29 @@ static int ValidatePCPMsg(pcp_info_t *pcp_msg_info)
return 0; return 0;
} }
/* RFC 6887, section 8.2: MUST return address mismatch if NAT if (pcp_msg_info->thirdp_ip) {
* in middle. (XXX n/a in thirdparty case) */ if (!GETFLAG(PCP_ALLOWTHIRDPARTYMASK)) {
if (memcmp(pcp_msg_info->int_ip, pcp_msg_info->result_code = PCP_ERR_UNSUPP_OPTION;
&pcp_msg_info->sender_ip, return 0;
sizeof(pcp_msg_info->sender_ip)) != 0) { }
pcp_msg_info->result_code = PCP_ERR_ADDRESS_MISMATCH;
return 0; /* RFC687, section 13.1 - if sender ip == THIRD_PARTY,
* it's an error. */
if (memcmp(pcp_msg_info->thirdp_ip,
&pcp_msg_info->sender_ip,
sizeof(pcp_msg_info->sender_ip)) == 0) {
pcp_msg_info->result_code = PCP_ERR_MALFORMED_REQUEST;
return 0;
}
} else {
/* RFC 6887, section 8.2: MUST return address mismatch if NAT
* in middle. */
if (memcmp(pcp_msg_info->int_ip,
&pcp_msg_info->sender_ip,
sizeof(pcp_msg_info->sender_ip)) != 0) {
pcp_msg_info->result_code = PCP_ERR_ADDRESS_MISMATCH;
return 0;
}
} }
/* protocol zero means 'all protocols' : internal port MUST be zero */ /* protocol zero means 'all protocols' : internal port MUST be zero */