samba 2:4.17.12+dfsg-0+deb12u1 source package in Debian

Changelog

samba (2:4.17.12+dfsg-0+deb12u1) bookworm-security; urgency=medium

  * new stable security bugfix release:
    o CVE-2023-3961: https://www.samba.org/samba/security/CVE-2023-3961.html
      Unsanitized pipe names allow SMB clients to connect as root
      to existing unix domain sockets on the file system.
    o CVE-2023-4091: https://www.samba.org/samba/security/CVE-2023-4091.html
      SMB client can truncate files to 0 bytes by opening files with OVERWRITE
      disposition when using the acl_xattr Samba VFS module with the smb.conf
      setting "acl_xattr:ignore system acls = yes"
    o CVE-2023-4154: https://www.samba.org/samba/security/CVE-2023-4154.html
      An RODC and a user with the GET_CHANGES right can view all attributes,
      including secrets and passwords.  Additionally, the access check fails
      open on error conditions.
    o CVE-2023-42669: https://www.samba.org/samba/security/CVE-2023-42669.html
      Calls to the rpcecho server on the AD DC can request that the server
      block for a user-defined amount of time, denying service.
    o CVE-2023-42670: https://www.samba.org/samba/security/CVE-2023-42670.html
      Samba can be made to start multiple incompatible RPC listeners,
      disrupting service on the AD DC.

 -- Michael Tokarev <email address hidden>  Tue, 10 Oct 2023 18:17:19 +0300

Upload details

Uploaded by:
Debian Samba Maintainers
Uploaded to:
Bookworm
Original maintainer:
Debian Samba Maintainers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Bookworm release main net

Builds

Downloads

File Size SHA-256 Checksum
samba_4.17.12+dfsg-0+deb12u1.dsc 4.4 KiB 30616f6b04bfb0d2878c61cd9295d79dd6cea5a05c529dc387b0ad135dbaf888
samba_4.17.12+dfsg.orig.tar.xz 17.4 MiB d01f7df9a7dca56ce3b145ee9f887ebd138665a76b61b99208044a8f43e9931d
samba_4.17.12+dfsg-0+deb12u1.debian.tar.xz 266.4 KiB 5ef5245bab0b690cd1ca4a20315d008795b1090a9b792922ac4f6796b618169d

No changes file available.

Binary packages built by this source