——————————————————————————–
Fedora Update Notification
FEDORA-2014-3796
2014-03-13 03:05:17
——————————————————————————–
Name : samba
Product : Fedora 20
Version : 4.1.6
Release : 1.fc20
URL : http://www.samba.org/
Summary : Server and Client software to interoperate with Windows machines
Description :
Samba is the standard Windows interoperability suite of programs for Linux and Unix.
——————————————————————————–
Update Information:
Fix CVE-2013-4496 and CVE-2013-6442.
——————————————————————————–
ChangeLog:
* Tue Mar 11 2014 – Andreas Schneider <asn@redhat.com> – 4.1.6-1
– Fix CVE-2013-4496 and CVE-2013-6442.
– Fix installation of pidl.
* Fri Feb 21 2014 – Andreas Schneider <asn@redhat.com> – 4.1.5-1
– Update to Samba 4.1.5.
* Fri Feb 7 2014 – Andreas Schneider <asn@redhat.com> – 4.1.4-1
– Update to Samba 4.1.4.
* Tue Dec 10 2013 – Guenther Deschner <gdeschner@redhat.com> – 4.1.3-2
– resolves: #1019469 – Fix winbind debug message NULL pointer derreference.
* Mon Dec 9 2013 – Andreas Schneider <asn@redhat.com> – 4.1.3-1
– Update to Samba 4.1.3.
– resolves: #1039454 – CVE-2013-4408.
– resolves: #1039500 – CVE-2012-6150.
* Mon Nov 25 2013 – Andreas Schneider <asn@redhat.com> – 4.1.2-1
– Update to Samba 4.1.2.
* Mon Nov 18 2013 – Guenther Deschner <gdeschner@redhat.com> – 4.1.1-3
– resolves: #948509 – Fix manpage correctness.
* Fri Nov 15 2013 – Andreas Schneider <asn@redhat.com> – 4.1.1-2
– related: #884169 – Fix strict aliasing warnings.
——————————————————————————–
References:
[ 1 ] Bug #1044099 – CVE-2013-6442 samba: smbcacls will delete ACL lists in certain circumstances
https://bugzilla.redhat.com/show_bug.cgi?id=1044099
[ 2 ] Bug #1072792 – CVE-2013-4496 samba: Password lockout not enforced for SAMR password changes
https://bugzilla.redhat.com/show_bug.cgi?id=1072792
——————————————————————————–
This update can be installed with the “yum” update program. Use
su -c ‘yum update samba’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce