samba 2:4.10.7+dfsg-0ubuntu2.2 source package in Ubuntu

Changelog

samba (2:4.10.7+dfsg-0ubuntu2.2) eoan-security; urgency=medium

  * SECURITY UPDATE: client code can return filenames containing path
    separators
    - debian/patches/CVE-2019-10218-1.patch: protect SMB1 client code
      from evil server returned names in source3/libsmb/clilist.c,
      source3/libsmb/proto.h.
    - debian/patches/CVE-2019-10218-2.patch: Protect SMB2 client code
      from evil server returned names in source3/libsmb/cli_smb2_fnum.c.
    - CVE-2019-10218
  * SECURITY UPDATE: Samba AD DC check password script does not receive the
    full password
    - debian/patches/CVE-2019-14833-1.patch: use utf8 characters in the
      unacceptable password in selftest/target/Samba4.pm.
    - debian/patches/CVE-2019-14833-2.patch: send full password to check
      password script in source4/dsdb/common/util.c.
    - CVE-2019-14833
  * SECURITY UPDATE: User with "get changes" permission can crash AD DC
    LDAP server via dirsync
    - debian/patches/CVE-2019-14847-1.patch: ensure attrs exist in
      source4/dsdb/samdb/ldb_modules/dirsync.c.
    - debian/patches/CVE-2019-14847-2.patch: demonstrate the correct
      interaction of ranged_results style attributes and dirsync in
      source4/dsdb/tests/python/dirsync.py.
    - debian/patches/CVE-2019-14847-3.patch: correct behaviour of
      ranged_results when combined with dirsync in
      source4/dsdb/samdb/ldb_modules/dirsync.c,
      source4/dsdb/samdb/ldb_modules/ranged_results.c.
    - CVE-2019-14847

 -- Marc Deslauriers <email address hidden>  Mon, 21 Oct 2019 07:36:00 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Eoan
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
samba_4.10.7+dfsg.orig.tar.xz 11.1 MiB 5dbd6f31e8e3cd2d94f773167f359efeeebab41c537a6d4950114f69237810e2
samba_4.10.7+dfsg-0ubuntu2.2.debian.tar.xz 242.6 KiB 31611282ea5ba705182de0c0a87ea073ba737bd2dce73969687fdf48fab3e6a0
samba_4.10.7+dfsg-0ubuntu2.2.dsc 4.1 KiB 288a353603276ac8a4af1cc597b6eb3855ab67875735d82ea80c5cd0972a23e0

View changes file

Binary packages built by this source

ctdb: No summary available for ctdb in ubuntu eoan.

No description available for ctdb in ubuntu eoan.

ctdb-dbgsym: No summary available for ctdb-dbgsym in ubuntu eoan.

No description available for ctdb-dbgsym in ubuntu eoan.

libnss-winbind: No summary available for libnss-winbind in ubuntu eoan.

No description available for libnss-winbind in ubuntu eoan.

libnss-winbind-dbgsym: No summary available for libnss-winbind-dbgsym in ubuntu eoan.

No description available for libnss-winbind-dbgsym in ubuntu eoan.

libpam-winbind: No summary available for libpam-winbind in ubuntu eoan.

No description available for libpam-winbind in ubuntu eoan.

libpam-winbind-dbgsym: No summary available for libpam-winbind-dbgsym in ubuntu eoan.

No description available for libpam-winbind-dbgsym in ubuntu eoan.

libparse-pidl-perl: No summary available for libparse-pidl-perl in ubuntu eoan.

No description available for libparse-pidl-perl in ubuntu eoan.

libsmbclient: No summary available for libsmbclient in ubuntu eoan.

No description available for libsmbclient in ubuntu eoan.

libsmbclient-dbgsym: No summary available for libsmbclient-dbgsym in ubuntu eoan.

No description available for libsmbclient-dbgsym in ubuntu eoan.

libsmbclient-dev: No summary available for libsmbclient-dev in ubuntu eoan.

No description available for libsmbclient-dev in ubuntu eoan.

libwbclient-dev: No summary available for libwbclient-dev in ubuntu eoan.

No description available for libwbclient-dev in ubuntu eoan.

libwbclient0: No summary available for libwbclient0 in ubuntu eoan.

No description available for libwbclient0 in ubuntu eoan.

libwbclient0-dbgsym: No summary available for libwbclient0-dbgsym in ubuntu eoan.

No description available for libwbclient0-dbgsym in ubuntu eoan.

python3-samba: No summary available for python3-samba in ubuntu eoan.

No description available for python3-samba in ubuntu eoan.

python3-samba-dbgsym: No summary available for python3-samba-dbgsym in ubuntu eoan.

No description available for python3-samba-dbgsym in ubuntu eoan.

registry-tools: No summary available for registry-tools in ubuntu eoan.

No description available for registry-tools in ubuntu eoan.

registry-tools-dbgsym: No summary available for registry-tools-dbgsym in ubuntu eoan.

No description available for registry-tools-dbgsym in ubuntu eoan.

samba: No summary available for samba in ubuntu eoan.

No description available for samba in ubuntu eoan.

samba-common: No summary available for samba-common in ubuntu eoan.

No description available for samba-common in ubuntu eoan.

samba-common-bin: No summary available for samba-common-bin in ubuntu eoan.

No description available for samba-common-bin in ubuntu eoan.

samba-common-bin-dbgsym: No summary available for samba-common-bin-dbgsym in ubuntu eoan.

No description available for samba-common-bin-dbgsym in ubuntu eoan.

samba-dbgsym: No summary available for samba-dbgsym in ubuntu eoan.

No description available for samba-dbgsym in ubuntu eoan.

samba-dev: No summary available for samba-dev in ubuntu eoan.

No description available for samba-dev in ubuntu eoan.

samba-dsdb-modules: No summary available for samba-dsdb-modules in ubuntu eoan.

No description available for samba-dsdb-modules in ubuntu eoan.

samba-dsdb-modules-dbgsym: No summary available for samba-dsdb-modules-dbgsym in ubuntu eoan.

No description available for samba-dsdb-modules-dbgsym in ubuntu eoan.

samba-libs: No summary available for samba-libs in ubuntu eoan.

No description available for samba-libs in ubuntu eoan.

samba-libs-dbgsym: No summary available for samba-libs-dbgsym in ubuntu eoan.

No description available for samba-libs-dbgsym in ubuntu eoan.

samba-testsuite: No summary available for samba-testsuite in ubuntu eoan.

No description available for samba-testsuite in ubuntu eoan.

samba-testsuite-dbgsym: No summary available for samba-testsuite-dbgsym in ubuntu eoan.

No description available for samba-testsuite-dbgsym in ubuntu eoan.

samba-vfs-modules: No summary available for samba-vfs-modules in ubuntu eoan.

No description available for samba-vfs-modules in ubuntu eoan.

samba-vfs-modules-dbgsym: No summary available for samba-vfs-modules-dbgsym in ubuntu eoan.

No description available for samba-vfs-modules-dbgsym in ubuntu eoan.

smbclient: No summary available for smbclient in ubuntu eoan.

No description available for smbclient in ubuntu eoan.

smbclient-dbgsym: No summary available for smbclient-dbgsym in ubuntu eoan.

No description available for smbclient-dbgsym in ubuntu eoan.

winbind: No summary available for winbind in ubuntu eoan.

No description available for winbind in ubuntu eoan.

winbind-dbgsym: No summary available for winbind-dbgsym in ubuntu eoan.

No description available for winbind-dbgsym in ubuntu eoan.