CVE-2020-1472(ZeroLogon): rpc_server/netlogon: Fix confounder check
authorGary Lockyer <gary@catalyst.net.nz>
Thu, 24 Sep 2020 01:35:47 +0000 (13:35 +1200)
committerAndrew Bartlett <abartlet@samba.org>
Fri, 16 Oct 2020 04:45:40 +0000 (04:45 +0000)
commitb9b6abf18b873ee83194405719fe993b8fb2073a
tree1f480234b1555283d74d788e567ae65bbe4080fa
parentc56c5c17fd4f5764935ee6a4cd90b9c0a2c525b4
CVE-2020-1472(ZeroLogon): rpc_server/netlogon: Fix confounder check

Add check for zero length confounder, to allow setting of passwords 512
bytes long. This does not need to be backported, as it is extremely
unlikely that anyone is using 512 byte passwords.

Signed-off-by: Gary Lockyer <gary@catalyst.net.nz>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
source3/rpc_server/netlogon/srv_netlog_nt.c
source4/rpc_server/netlogon/dcerpc_netlogon.c