CVE-2015-5370: dcerpc.idl: add DCERPC_{NCACN_PAYLOAD,FRAG}_MAX_SIZE defines
authorStefan Metzmacher <metze@samba.org>
Thu, 16 Jul 2015 20:46:05 +0000 (22:46 +0200)
committerStefan Metzmacher <metze@samba.org>
Tue, 12 Apr 2016 17:25:28 +0000 (19:25 +0200)
BUG: https://bugzilla.samba.org/show_bug.cgi?id=11344

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Günther Deschner <gd@samba.org>
librpc/idl/dcerpc.idl

index f7bf59542b2b3a1d056c07abf619f555dc2de140..015eb3d181516fccb9491971b713811994598c26 100644 (file)
@@ -532,8 +532,10 @@ interface dcerpc
        const uint8 DCERPC_PFC_OFFSET      =  3;
        const uint8 DCERPC_DREP_OFFSET     =  4;
        const uint8 DCERPC_FRAG_LEN_OFFSET =  8;
+       const uint32 DCERPC_FRAG_MAX_SIZE  = 5840;
        const uint8 DCERPC_AUTH_LEN_OFFSET = 10;
        const uint8 DCERPC_NCACN_PAYLOAD_OFFSET = 16;
+       const uint32 DCERPC_NCACN_PAYLOAD_MAX_SIZE = 0x400000; /* 4 MByte */
 
        /* little-endian flag */
        const uint8 DCERPC_DREP_LE  = 0x10;