CVE-2021-23192: dcesrv_core: only the first fragment specifies the auth_contexts
authorStefan Metzmacher <metze@samba.org>
Mon, 16 Nov 2020 13:15:06 +0000 (14:15 +0100)
committerJule Anger <janger@samba.org>
Tue, 9 Nov 2021 19:45:34 +0000 (19:45 +0000)
commit871d672f51fa8de6b2a4feee2039b76654e6aad2
treefe9ca176b12f0a3ea4cd64f864c6abae010721ac
parent9ebc679e76803e41861b9901d69fee41d3ce9a0f
CVE-2021-23192: dcesrv_core: only the first fragment specifies the auth_contexts

All other fragments blindly inherit it.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=14875

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Samuel Cabrero <scabrero@samba.org>
librpc/rpc/dcerpc_pkt_auth.c
librpc/rpc/dcerpc_pkt_auth.h
librpc/rpc/dcesrv_auth.c
librpc/rpc/dcesrv_core.c
selftest/knownfail.d/dcerpc-auth-fraq [deleted file]
source4/librpc/rpc/dcerpc.c