CVE-2018-1057: s4:dsdb/acl: changing dBCSPwd is only allowed with a control
authorRalph Boehme <slow@samba.org>
Thu, 15 Feb 2018 22:11:38 +0000 (23:11 +0100)
committerStefan Metzmacher <metze@samba.org>
Tue, 13 Mar 2018 09:24:27 +0000 (10:24 +0100)
commit50e7788603b97104fe116a07ab14a1d1148f4405
treef1df55f044d8b0bdd5ed8b6e8a4f096ad8258e30
parentc80456855197f9fe9ef497a7fc94504c28445343
CVE-2018-1057: s4:dsdb/acl: changing dBCSPwd is only allowed with a control

This is not strictly needed to fig bug 13272, but it makes sense to also
fix this while fixing the overall ACL checking logic.

Bug: https://bugzilla.samba.org/show_bug.cgi?id=13272

Signed-off-by: Ralph Boehme <slow@samba.org>
Reviewed-by: Stefan Metzmacher <metze@samba.org>
source4/dsdb/samdb/ldb_modules/acl.c