LWN.net Logo

Fedora alert FEDORA-2013-1654 (samba)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 18 Update: samba-4.0.2-1.fc18
Date:  Tue, 12 Feb 2013 05:06:25 +0000
Message-ID:  <20130212050625.6B41920ABC@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-1654 2013-02-01 15:45:20 -------------------------------------------------------------------------------- Name : samba Product : Fedora 18 Version : 4.0.2 Release : 1.fc18 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. -------------------------------------------------------------------------------- Update Information: Update to version 4.0.2 which fixes CVE-2013-0213 and CVE-2013-0214. -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 30 2013 - Andreas Schneider <asn@redhat.com> - 2:4.0.2-1 - Update to Samba 4.0.2. - Fixes CVE-2013-0213. - Fixes CVE-2013-0214. - resolves: #906002 - resolves: #905700 - resolves: #905704 - Fix conn->share_access which is reset between user switches. - resolves: #903806 - Add missing example and make sure we don't introduce perl dependencies. - resolves: #639470 * Wed Jan 16 2013 - Andreas Schneider <asn@redhat.com> - 2:4.0.1-1 - Update to Samba 4.0.1. - Fixes CVE-2013-0172. * Mon Dec 17 2012 - Andreas Schneider <asn@redhat.com> - 2:4.0.0-174 - Fix typo in winbind-krb-locator post uninstall script. * Tue Dec 11 2012 - Andreas Schneider <asn@redhat.com> - 2:4.0.0-173 - Update to Samba 4.0.0. * Thu Dec 6 2012 - Andreas Schneider <asn@redhat.com> - 2:4.0.0-171.rc6 - Fix typo in winbind-krb-locator post uninstall script. * Tue Dec 4 2012 - Andreas Schneider <asn@redhat.com> - 2:4.0.0-170.rc6 - Update to Samba 4.0.0rc6. - Add /etc/pam.d/samba for swat to work correctly. - resolves #882700 * Fri Nov 23 2012 Guenther Deschner <gdeschner@redhat.com> - 2:4.0.0-169.rc5 - Make sure ncacn_ip_tcp client code looks for NBT_NAME_SERVER name types. -------------------------------------------------------------------------------- References: [ 1 ] Bug #905700 - CVE-2013-0213 samba: clickjacking vulnerability in SWAT https://bugzilla.redhat.com/show_bug.cgi?id=905700 [ 2 ] Bug #905704 - CVE-2013-0214 samba: cross-site request forgery vulnerability in SWAT https://bugzilla.redhat.com/show_bug.cgi?id=905704 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update samba' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds