CVE-2014-8143:dsdb-samldb: Check for extended access rights before we allow changes...
authorAndrew Bartlett <abartlet@samba.org>
Thu, 4 Dec 2014 04:23:29 +0000 (17:23 +1300)
committerKarolin Seeger <kseeger@samba.org>
Thu, 15 Jan 2015 19:18:07 +0000 (20:18 +0100)
commit2a699e4e1168c473cf88c40db8efa1eab1bc17a2
tree17775beaa05c97a8bee79fd4c8ea5f209e8e7d33
parentdf1f7ce906a17d916e6faeb495efdab01e2759bf
CVE-2014-8143:dsdb-samldb: Check for extended access rights before we allow changes to userAccountControl

This requires an additional control to be used in the
LSA server to add domain trust account objects.

Bug: https://bugzilla.samba.org/show_bug.cgi?id=10993

Signed-off-by: Andrew Bartlett <abartlet@samba.org>
Reviewed-by: Garming Sam <garming@catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze@samba.org>
librpc/idl/security.idl
source4/dsdb/samdb/ldb_modules/samldb.c
source4/dsdb/samdb/samdb.h
source4/rpc_server/lsa/dcesrv_lsa.c
source4/setup/schema_samba4.ldif