CVE-2014-8143:dsdb-samldb: Check for extended access rights before we allow changes...
authorAndrew Bartlett <abartlet@samba.org>
Thu, 4 Dec 2014 04:23:29 +0000 (17:23 +1300)
committerKarolin Seeger <kseeger@samba.org>
Mon, 12 Jan 2015 20:04:47 +0000 (21:04 +0100)
commit3d221efd635601e8f1ba08e018a248472a36d5df
treeea3a38f0c3272c0e128f096c28318a371a8b1415
parent01a4bd717e1ae61f207bd0ae3109ee20846ff426
CVE-2014-8143:dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl

This requires an additional control to be used in the
LSA server to add domain trust account objects.

Bug: https://bugzilla.samba.org/show_bug.cgi?id=10993

Signed-off-by: Andrew Bartlett <abartlet@samba.org>
Reviewed-by: Stefan Metzmacher <metze@samba.org>
librpc/idl/security.idl
source4/dsdb/samdb/ldb_modules/samldb.c
source4/dsdb/samdb/samdb.h
source4/rpc_server/lsa/dcesrv_lsa.c
source4/setup/schema_samba4.ldif