diff options
author | Andrew Bartlett <abartlet@samba.org> | 2020-03-11 16:43:31 +1300 |
---|---|---|
committer | Karolin Seeger <kseeger@samba.org> | 2020-04-21 13:20:31 +0200 |
commit | 980831bb97c0caca95cf1d24d475f829f3c0a1d1 (patch) | |
tree | 302712b441dfbd3cf8db07388de18cab9211a26a /source3 | |
parent | 24e621b4dde15a26f4fbf1a2e2bc7ecdb77d26a4 (diff) | |
download | samba-980831bb97c0caca95cf1d24d475f829f3c0a1d1.tar.gz |
CVE-2020-10700: dsdb: Do not permit the ASQ control for the GUID search in paged_results
ASQ is a very strange control and a BASE search can return multiple results
that are NOT the requested DN, but the DNs pointed to by it!
Thanks to Andrei Popa <andrei.popa@next-gen.ro> for finding,
reporting and working with us to diagnose this issue!
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14331
Signed-off-by: Andrew Bartlett <abartlet@samba.org>
Reviewed-by: Gary Lockyer <gary@catalyst.net.nz>
Diffstat (limited to 'source3')
0 files changed, 0 insertions, 0 deletions