From 972f293e46d936ade9613abfeb0953936f7389a5 Mon Sep 17 00:00:00 2001 From: Michael Brown Date: Sat, 8 Sep 2007 19:30:25 +0100 Subject: [PATCH] Check for correct block number in tftp_rx_data(). (Problem observed by Clay McClure in VMware Fusion.) --- src/net/udp/tftp.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/src/net/udp/tftp.c b/src/net/udp/tftp.c index 74c8c0a5..194c533d 100644 --- a/src/net/udp/tftp.c +++ b/src/net/udp/tftp.c @@ -415,7 +415,7 @@ static int tftp_rx_oack ( struct tftp_request *tftp, void *buf, size_t len ) { static int tftp_rx_data ( struct tftp_request *tftp, struct io_buffer *iobuf ) { struct tftp_data *data = iobuf->data; - unsigned int block; + int block; size_t data_len; int rc; @@ -432,6 +432,14 @@ static int tftp_rx_data ( struct tftp_request *tftp, iob_pull ( iobuf, sizeof ( *data ) ); data_len = iob_len ( iobuf ); + /* Check for correct block */ + if ( block != ( tftp->state + 1 ) ) { + DBGC ( tftp, "TFTP %p received out-of-order block %d " + "(expecting %d)\n", tftp, block, ( tftp->state + 1 ) ); + free_iob ( iobuf ); + return 0; + } + /* Deliver data */ if ( ( rc = xfer_deliver_iob ( &tftp->xfer, iobuf ) ) != 0 ) { DBGC ( tftp, "TFTP %p could not deliver data: %s\n",