From: Russell Bryant Date: Tue, 24 Apr 2007 21:34:53 +0000 (+0000) Subject: Merged revisions 61786 via svnmerge from X-Git-Tag: 1.4.3~3^2 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=5bee74171dd10b012a0cd6f50dff1cce15526ca3;p=thirdparty%2Fasterisk.git Merged revisions 61786 via svnmerge from https://origsvn.digium.com/svn/asterisk/branches/1.2 ........ r61786 | russell | 2007-04-24 16:33:59 -0500 (Tue, 24 Apr 2007) | 4 lines Don't crash if a manager connection provides a username that exists in manager.conf but does not have a password, and also requests MD5 authentication. (ASA-2007-012) ........ git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/1.4@61787 65c4cc65-6c06-0410-ace0-fbb531ad65f3 --- diff --git a/main/manager.c b/main/manager.c index 7c2e1b37a1..e364fcfdbd 100644 --- a/main/manager.c +++ b/main/manager.c @@ -926,7 +926,8 @@ static int authenticate(struct mansession *s, const struct message *m) } else if (ha) ast_free_ha(ha); if (!strcasecmp(authtype, "MD5")) { - if (!ast_strlen_zero(key) && s->challenge) { + if (!ast_strlen_zero(key) && + !ast_strlen_zero(s->challenge) && !ast_strlen_zero(password)) { int x; int len = 0; char md5key[256] = "";