wok-6.x view samba/stuff/CVE-2017-7494.u @ rev 20318

revert back to v4.4,since glib +gtk error :-( probably v4.6.3 would work, but cannot find it on dev server
author Erkan Yilmaz <erkan@slitaz.org>
date Sun May 20 11:19:35 2018 +0000 (2018-05-20)
parents
children
line source
1 CVE-2017-7494: rpc_server3: Refuse to open pipe names with / inside
2 --- source3/rpc_server/srv_pipe.c
3 +++ source3/rpc_server/srv_pipe.c
4 @@ -384,6 +384,11 @@ bool is_known_pipename(const char *pipename, struct ndr_syntax_id *syntax)
5 {
6 NTSTATUS status;
8 + if (strchr(pipename, '/')) {
9 + DEBUG(1, ("Refusing open on pipe %s\n", pipename));
10 + return false;
11 + }
12 +
13 if (lp_disable_spoolss() && strequal(pipename, "spoolss")) {
14 DEBUG(10, ("refusing spoolss access\n"));
15 return false;