CVE-2016-2118: s4:rpc_server: make use of "allow dcerpc auth level connect"
authorStefan Metzmacher <metze@samba.org>
Thu, 10 Mar 2016 01:46:59 +0000 (02:46 +0100)
committerStefan Metzmacher <metze@samba.org>
Tue, 12 Apr 2016 17:25:27 +0000 (19:25 +0200)
commit991dddd06d6aa62375d47dfdea7fea6501b93e0c
treef58545ce7a547ba0aeec45c7c05317f2ed0db186
parent06b038c017234f1eae35f4c316a0d105cc4d1061
CVE-2016-2118: s4:rpc_server: make use of "allow dcerpc auth level connect"

With this option turned off we only allow DCERPC_AUTH_LEVEL_{NONE,INTEGRITY,PRIVACY},
this means the reject any request with AUTH_LEVEL_CONNECT with ACCESS_DENIED.

We sadly need to keep this enabled by default for now.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=11616

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Günther Deschner <gd@samba.org>
source4/rpc_server/dcerpc_server.c
source4/rpc_server/dcerpc_server.h