[Buildroot] [PATCH 1/1] package/samba4: security bump version to 4.18.5

Peter Korsgaard peter at korsgaard.com
Sat Aug 26 17:41:00 UTC 2023


>>>>> "Bernd" == Bernd Kuhls <bernd at kuhls.net> writes:

 > Release notes: https://www.samba.org/samba/history/samba-4.18.5.html
 > Fixes the following CVEs:

 > o CVE-2022-2127:
 > When winbind is used for NTLM authentication, a maliciously
 > crafted request can trigger an out-of-bounds read in winbind
 > and possibly crash it.
 > https://www.samba.org/samba/security/CVE-2022-2127.html

 > o CVE-2023-3347:
 > SMB2 packet signing is not enforced if an admin configured
 > "server signing = required" or for SMB2 connections to Domain
 > Controllers where SMB2 packet signing is mandatory.
 > https://www.samba.org/samba/security/CVE-2023-3347.html

 > o CVE-2023-34966:
 > An infinite loop bug in Samba's mdssvc RPC service for
 > Spotlight can be triggered by an unauthenticated attacker by
 > issuing a malformed RPC request.
 > https://www.samba.org/samba/security/CVE-2023-34966.html

 > o CVE-2023-34967:
 > Missing type validation in Samba's mdssvc RPC service for
 > Spotlight can be used by an unauthenticated attacker to
 > trigger a process crash in a shared RPC mdssvc worker process.
 > https://www.samba.org/samba/security/CVE-2023-34967.html

 > o CVE-2023-34968:
 > As part of the Spotlight protocol Samba discloses the server-
 > side absolute path of shares and files and directories in
 > search results.
 > https://www.samba.org/samba/security/CVE-2023-34968.html

 > Signed-off-by: Bernd Kuhls <bernd at kuhls.net>

Looks like the 4.15.x version is EOL, so applied to 2023.02.x and
2023.05.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list