[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: (ITS#3472) return code should be 32 when no access to object
Of course, all my dscussion about write operations may sound academic,
because writes need authentication; I guess we better focus on reads
right now. Another note is: we don't check entry access for compares;
this means that a compare should return noSuchObject as well if no
disclose is granted for that entry, otherwise attackers could exploit it.
p.
SysNet - via Dossi,8 27100 Pavia Tel: +390382573859 Fax: +390382476497