samba 2:4.11.6+dfsg-0ubuntu1.1 source package in Ubuntu

Changelog

samba (2:4.11.6+dfsg-0ubuntu1.1) focal-security; urgency=medium

  * SECURITY UPDATE: Use-after-free in AD DC LDAP server
    - debian/patches/CVE-2020-10700-1.patch: add test for ASQ and ASQ in
      combination with paged_results in selftest/knownfail.d/asq,
      source4/dsdb/tests/python/asq.py, source4/selftest/tests.py.
    - debian/patches/CVE-2020-10700-3.patch: do not permit the ASQ control
      for the GUID search in paged_results in selftest/knownfail.d/asq,
      source4/dsdb/samdb/ldb_modules/paged_results.c.
    - debian/control: bump libldb-dev, python3-ldb, and python3-ldb-dev
      Build-Depends to 2.0.10.
    - CVE-2020-10700
  * SECURITY UPDATE: Stack overflow in AD DC LDAP server
    - debian/patches/CVE-2020-10704-1.patch: add ASN.1 max tree depth in
      auth/gensec/gensec_util.c, lib/util/asn1.c, lib/util/asn1.h,
      lib/util/tests/asn1_tests.c, libcli/auth/spnego_parse.c,
      libcli/cldap/cldap.c, libcli/ldap/ldap_message.c,
      source3/lib/tldap.c, source3/lib/tldap_util.c,
      source3/libsmb/clispnego.c, source3/torture/torture.c,
      source4/auth/gensec/gensec_krb5.c, source4/ldap_server/ldap_server.c,
      source4/libcli/ldap/ldap_client.c,
      source4/libcli/ldap/ldap_controls.c.
    - debian/patches/CVE-2020-10704-3.patch: check parse tree depth in
      lib/util/asn1.c.
    - debian/patches/CVE-2020-10704-5.patch: add max ldap request sizes in
      docs-xml/smbdotconf/ldap/ldapmaxanonrequest.xml,
      docs-xml/smbdotconf/ldap/ldapmaxauthrequest.xml,
      lib/param/loadparm.c, source3/param/loadparm.c.
    - debian/patches/CVE-2020-10704-6.patch: limit request sizes in
      source4/ldap_server/ldap_server.c.
    - debian/patches/CVE-2020-10704-7.patch: add search size limits to
      ldap_decode in docs-xml/smbdotconf/ldap/ldapmaxsearchrequest.xml,
      lib/param/loadparm.c, libcli/cldap/cldap.c,
      libcli/ldap/ldap_message.c, libcli/ldap/ldap_message.h,
      source3/param/loadparm.c, source4/ldap_server/ldap_server.c,
      source4/libcli/ldap/ldap_client.c.
    - debian/patches/CVE-2020-10704-8.patch: check search request lengths
      in lib/util/asn1.c, lib/util/asn1.h, libcli/ldap/ldap_message.c.
    - CVE-2020-10704

 -- Marc Deslauriers <email address hidden>  Fri, 24 Apr 2020 08:08:38 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
samba_4.11.6+dfsg.orig.tar.xz 11.1 MiB 5e270d46cf79db1bfb3155d207291ea05b8b7d7094d7eef13317b9a5cc2e33d5
samba_4.11.6+dfsg-0ubuntu1.1.debian.tar.xz 256.5 KiB 113d6142bd21cc1071a5ca39c9fcce52f89a4c2da74083805f54a5aac21be4dc
samba_4.11.6+dfsg-0ubuntu1.1.dsc 4.3 KiB 625586fedcdd959c24fd5c4fc801ecadc0b28bcdac41d31a8095daa6e1e3dada

View changes file

Binary packages built by this source

ctdb: No summary available for ctdb in ubuntu groovy.

No description available for ctdb in ubuntu groovy.

ctdb-dbgsym: debug symbols for ctdb
libnss-winbind: Samba nameservice integration plugins

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file and printer sharing with
 Microsoft Windows, OS X, and other Unix systems. Samba can also function
 as an NT4-style domain controller, and can integrate with both NT4 domains
 and Active Directory realms as a member server.
 .
 This package provides nss_winbind, a plugin that integrates
 with a local winbindd server to provide user/group name lookups to the
 system; and nss_wins, which provides hostname lookups via both the NBNS and
 NetBIOS broadcast protocols.

libnss-winbind-dbgsym: debug symbols for libnss-winbind
libpam-winbind: No summary available for libpam-winbind in ubuntu groovy.

No description available for libpam-winbind in ubuntu groovy.

libpam-winbind-dbgsym: debug symbols for libpam-winbind
libsmbclient: No summary available for libsmbclient in ubuntu groovy.

No description available for libsmbclient in ubuntu groovy.

libsmbclient-dbgsym: No summary available for libsmbclient-dbgsym in ubuntu groovy.

No description available for libsmbclient-dbgsym in ubuntu groovy.

libsmbclient-dev: No summary available for libsmbclient-dev in ubuntu groovy.

No description available for libsmbclient-dev in ubuntu groovy.

libwbclient-dev: No summary available for libwbclient-dev in ubuntu groovy.

No description available for libwbclient-dev in ubuntu groovy.

libwbclient0: Samba winbind client library

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file and printer sharing with
 Microsoft Windows, OS X, and other Unix systems.
 .
 This package provides a library for client applications that interact
 via the winbind pipe protocol with a Samba winbind server.

libwbclient0-dbgsym: No summary available for libwbclient0-dbgsym in ubuntu groovy.

No description available for libwbclient0-dbgsym in ubuntu groovy.

python3-samba: Python 3 bindings for Samba

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file sharing with Microsoft Windows, OS X,
 and other Unix systems. Samba can also function as a domain controller
 or member server in both NT4-style and Active Directory domains.
 .
 This package contains Python 3 bindings for most Samba libraries.

python3-samba-dbgsym: debug symbols for python3-samba
registry-tools: tools for viewing and manipulating the Windows registry

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file sharing with Microsoft Windows, OS X,
 and other Unix systems. Samba can also function as a domain controller
 or member server in both NT4-style and Active Directory domains.
 .
 This package contains tools for viewing and manipulating the binary
 "registry" found on Windows machines, both locally and remote.

registry-tools-dbgsym: No summary available for registry-tools-dbgsym in ubuntu groovy.

No description available for registry-tools-dbgsym in ubuntu groovy.

samba: No summary available for samba in ubuntu groovy.

No description available for samba in ubuntu groovy.

samba-common: common files used by both the Samba server and client

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file and printer sharing with
 Microsoft Windows, OS X, and other Unix systems.
 .
 This package contains common files used by all parts of Samba.

samba-common-bin: No summary available for samba-common-bin in ubuntu groovy.

No description available for samba-common-bin in ubuntu groovy.

samba-common-bin-dbgsym: No summary available for samba-common-bin-dbgsym in ubuntu groovy.

No description available for samba-common-bin-dbgsym in ubuntu groovy.

samba-dbgsym: debug symbols for samba
samba-dev: No summary available for samba-dev in ubuntu groovy.

No description available for samba-dev in ubuntu groovy.

samba-dsdb-modules: Samba Directory Services Database

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file sharing with Microsoft Windows, OS X,
 and other Unix systems. Samba can also function as a domain controller
 or member server in both NT4-style and Active Directory domains.
 .
 This package contains LDB plugins which add support for various Active
 Directory features to the LDB library.

samba-dsdb-modules-dbgsym: No summary available for samba-dsdb-modules-dbgsym in ubuntu groovy.

No description available for samba-dsdb-modules-dbgsym in ubuntu groovy.

samba-libs: Samba core libraries

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file sharing with Microsoft Windows, OS X,
 and other Unix systems. Samba can also function as a domain controller
 or member server in both NT4-style and Active Directory domains.
 .
 This package contains the shared libraries.

samba-libs-dbgsym: No summary available for samba-libs-dbgsym in ubuntu groovy.

No description available for samba-libs-dbgsym in ubuntu groovy.

samba-testsuite: test suite from Samba

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file sharing with Microsoft Windows, OS X,
 and other Unix systems. Samba can also function as a domain controller
 or member server in both NT4-style and Active Directory domains.
 .
 This package contains programs for testing the reliability and speed
 of SMB servers, Samba in particular.

samba-testsuite-dbgsym: No summary available for samba-testsuite-dbgsym in ubuntu groovy.

No description available for samba-testsuite-dbgsym in ubuntu groovy.

samba-vfs-modules: No summary available for samba-vfs-modules in ubuntu groovy.

No description available for samba-vfs-modules in ubuntu groovy.

samba-vfs-modules-dbgsym: debug symbols for samba-vfs-modules
smbclient: No summary available for smbclient in ubuntu groovy.

No description available for smbclient in ubuntu groovy.

smbclient-dbgsym: No summary available for smbclient-dbgsym in ubuntu groovy.

No description available for smbclient-dbgsym in ubuntu groovy.

winbind: service to resolve user and group information from Windows NT servers

 Samba is an implementation of the SMB/CIFS protocol for Unix systems,
 providing support for cross-platform file sharing with Microsoft Windows, OS X,
 and other Unix systems. Samba can also function as a domain controller
 or member server in both NT4-style and Active Directory domains.
 .
 This package provides winbindd, a daemon which integrates authentication
 and directory service (user/group lookup) mechanisms from a Windows
 domain on a Linux system.
 .
 Winbind based user/group lookups via /etc/nsswitch.conf can be enabled via
 the libnss-winbind package. Winbind based Windows domain authentication can
 be enabled via the libpam-winbind package.

winbind-dbgsym: No summary available for winbind-dbgsym in ubuntu groovy.

No description available for winbind-dbgsym in ubuntu groovy.