summaryrefslogtreecommitdiff
path: root/README.md
diff options
context:
space:
mode:
authorGary Lockyer <gary@catalyst.net.nz>2020-04-08 08:49:23 +1200
committerKarolin Seeger <kseeger@samba.org>2020-04-22 12:50:42 +0200
commitdb78f2667eb51c106c66edebcf66914ea580bfc6 (patch)
tree7a3fd1e016a79e22e0aca35c9a4ff9d316987860 /README.md
parent8729c05b1cd6a63d9f8e163b2e438007db3eb4f8 (diff)
downloadsamba-db78f2667eb51c106c66edebcf66914ea580bfc6.tar.gz
CVE-2020-10704: libcli ldap_message: Add search size limits to ldap_decode
Add search request size limits to ldap_decode calls. The ldap server uses the smb.conf variable "ldap max search request size" which defaults to 250Kb. For cldap the limit is hard coded as 4096. Credit to OSS-Fuzz REF: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20454 BUG: https://bugzilla.samba.org/show_bug.cgi?id=14334 Signed-off-by: Gary Lockyer <gary@catalyst.net.nz> Reviewed-by: Andrew Bartlett <abartlet@samba.org>
Diffstat (limited to 'README.md')
0 files changed, 0 insertions, 0 deletions