|
|
Subscribe / Log in / New account

Fedora alert FEDORA-2018-8e4d871867 (samba)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 27 Update: samba-4.7.9-0.fc27
Date:  Wed, 22 Aug 2018 00:46:40 +0000 (UTC)
Message-ID:  <20180822004640.9951F624F57A@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-8e4d871867 2018-08-22 00:45:21.818676 -------------------------------------------------------------------------------- Name : samba Product : Fedora 27 Version : 4.7.9 Release : 0.fc27 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. -------------------------------------------------------------------------------- Update Information: Update to Samba 4.7.9, Security fix for CVE-2018-1139, CVE-2018-1140, CVE-2018-10858, CVE-2018-10918, CVE-2018-10919 -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 14 2018 Guenther Deschner <gdeschner@redhat.com> - 4.7.9-0 - Update to Samba 4.7.9 - resolves: #1589651, #1617916 - Security fixes for CVE-2018-1139 - resolves: #1580230, #1618613 - Security fixes for CVE-2018-1140 - resolves: #1612805, #1618697 - Security fixes for CVE-2018-10858 - resolves: #1610640, #1617910 - Security fixes for CVE-2018-10918 - resolves: #1610645, #1617911 - Security fixes for CVE-2018-10919 * Thu Jun 21 2018 Guenther Deschner <gdeschner@redhat.com> - 4.7.8-0 - Update to Samba 4.7.8 * Tue Apr 17 2018 Guenther Deschner <gdeschner@redhat.com> - 4.7.7-0 - Update to Samba 4.7.7 * Tue Mar 13 2018 Guenther Deschner <gdeschner@redhat.com> - 4.7.6-0 - Update to Samba 4.7.6 - resolves: #1554754, #1554756 - Security fixes for CVE-2018-1050 CVE-2018-1057 * Wed Feb 7 2018 Guenther Deschner <gdeschner@redhat.com> - 4.7.5-2 - Update to Samba 4.7.5 * Mon Jan 15 2018 Andreas Schneider <asn@redhat.com> - 4.7.4-2 - Rebuild for libtalloc and libldb * Mon Jan 8 2018 Andreas Schneider <asn@redhat.com> - 4.7.4-1 - resolves: #1508092 - Add missing dependency for tdbbackup * Mon Dec 25 2017 Guenther Deschner <gdeschner@redhat.com> - 4.7.4-0 - Update to Samba 4.7.4 * Mon Dec 4 2017 Andreas Schneider <asn@redhat.com> - 4.7.3-3 - resolves: #1520163 - Link libaesni-intel-samba4.so with -z noexecstack * Thu Nov 30 2017 Andreas Schneider <asn@redhat.com> - 4.7.3-2 - Fix deamon startup with systemd * Thu Nov 23 2017 Bastien Nocera <bnocera@redhat.com> - 4.7.3-1 - Enable AES acceleration on Intel compatible CPUs by default * Tue Nov 21 2017 Guenther Deschner <gdeschner@redhat.com> - 4.7.3-0 - Update to Samba 4.7.3 - resolves: #1515692 - Security fix for CVE-2017-14746 and CVE-2017-15275 * Wed Nov 15 2017 Guenther Deschner <gdeschner@redhat.com> - 4.7.2-0 - resolves: #1513452 - Update to Samba 4.7.2 * Thu Nov 2 2017 Guenther Deschner <gdeschner@redhat.com> - 4.7.1-0 - resolves: #1508871 - Update to Samba 4.7.1 * Mon Oct 30 2017 Alexander Bokovoy <abokovoy@redhat.com> - 4.7.0-18 - Force samba-dc to use the same libldb version as LDB modules compiled - resolves: #1507420 - LDB / Samba module version mismatch * Fri Oct 27 2017 Andreas Schneider <asn@redhat.com> - 4.7.0-17 - Move dsdb libs to python2-samba-dc * Thu Oct 26 2017 Andreas Schneider <asn@redhat.com> - 4.7.0-16 - Create python[2|3]-samba-dc packages * Wed Oct 25 2017 Andreas Schneider <asn@redhat.com> - 4.7.0-15 - Fix several dependency issues - related: #1499140 - Fix several dependency issues * Fri Oct 13 2017 Andreas Schneider <asn@redhat.com> - 4.7.0-14 - resolves: #1499140 - Move libdfs-server-ad to the correct subpackage * Fri Oct 6 2017 Alexander Bokovoy <abokovoy@redhat.com> - 4.7.0-13 - Move /usr/lib{64,}/samba/libdsdb-garbage-collect-tombstones-samba4.so to samba-dc-libs - Rebuild in rawhide against new krb5 1.16 and docbook-xml -------------------------------------------------------------------------------- References: [ 1 ] Bug #1589651 - CVE-2018-1139 samba: Weak authentication protocol regression https://bugzilla.redhat.com/show_bug.cgi?id=1589651 [ 2 ] Bug #1580230 - CVE-2018-1140 samba: LDAP server crash via distinguishedName https://bugzilla.redhat.com/show_bug.cgi?id=1580230 [ 3 ] Bug #1612805 - CVE-2018-10858 samba: insufficient input validation in libsmbclient https://bugzilla.redhat.com/show_bug.cgi?id=1612805 [ 4 ] Bug #1610640 - CVE-2018-10918 samba: DsCrackNames on a user without an SPN can trigger NULL-pointer de-reference https://bugzilla.redhat.com/show_bug.cgi?id=1610640 [ 5 ] Bug #1610645 - CVE-2018-10919 samba: Confidential attribute disclosure via substring search https://bugzilla.redhat.com/show_bug.cgi?id=1610645 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-8e4d871867' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds