CVE-2016-2019: s3:libsmb: add comment regarding smbXcli_session_is_guest() with manda...
authorStefan Metzmacher <metze@samba.org>
Thu, 28 Apr 2016 00:36:35 +0000 (02:36 +0200)
committerKarolin Seeger <kseeger@samba.org>
Tue, 5 Jul 2016 07:21:54 +0000 (09:21 +0200)
BUG: https://bugzilla.samba.org/show_bug.cgi?id=11860

Signed-off-by: Stefan Metzmacher <metze@samba.org>
source3/libsmb/cliconnect.c

index 420fe3c5e04ac3fcd609d5e225e4524f7fc8d0ba..3de379616b53b10f9c708c4ea76f1fe4ef2b8625 100644 (file)
@@ -1606,6 +1606,9 @@ static void cli_session_setup_gensec_remote_done(struct tevent_req *subreq)
                         * have a negotiated session key.
                         *
                         * So just pretend we are completely done.
+                        *
+                        * Note that smbXcli_session_is_guest()
+                        * always returns false if we require signing.
                         */
                        state->blob_in = data_blob_null;
                        state->local_ready = true;