1
0
mirror of https://github.com/samba-team/samba.git synced 2024-12-23 17:34:34 +03:00
samba-mirror/source4/ldap_server
Gary Lockyer 3149ea0a8a CVE-2020-10704: libcli ldap_message: Add search size limits to ldap_decode
Add search request size limits to ldap_decode calls.

The ldap server uses the smb.conf variable
"ldap max search request size" which defaults to 250Kb.
For cldap the limit is hard coded as 4096.

Credit to OSS-Fuzz

REF: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20454
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14334

Signed-off-by: Gary Lockyer <gary@catalyst.net.nz>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
2020-05-04 02:59:32 +00:00
..
devdocs
ldap_backend.c ldap_server: Regression in 0559430ab6 2019-07-11 05:25:26 +00:00
ldap_bind.c s4/ldap_bind: notice backend init failure 2019-05-10 01:15:16 +00:00
ldap_extended.c s4:ldap_server: add support for async notification requests 2016-02-17 03:43:23 +01:00
ldap_server.c CVE-2020-10704: libcli ldap_message: Add search size limits to ldap_decode 2020-05-04 02:59:32 +00:00
ldap_server.h ldap server: generate correct referral schemes 2019-05-24 05:12:14 +00:00
wscript_build ldap_server: Log access without a bind 2017-03-29 02:37:27 +02:00