Karolin Seeger
2019-Sep-03 07:31 UTC
[Announce] Samba 4.10.8 and 4.9.13 Security Releases Available
Release Announcements --------------------- These are a security releases in order to address the following defect: o CVE-2019-10197: Combination of parameters and permissions can allow user to escape from the share path definition. ======Details ====== o CVE-2019-10197: Under certain parameter configurations, when an SMB client accesses a network share and the user does not have permission to access the share root directory, it is possible for the user to escape from the share to see the complete '/' filesystem. Unix permission checks in the kernel are still enforced. Changes: -------- o Jeremy Allison <jra at samba.org> * BUG 14035: CVE-2019-10197: Permissions check deny can allow user to escape from the share. o Stefan Metzmacher <metze at samba.org> * BUG 14035: CVE-2019-10197: Permissions check deny can allow user to escape from the share. ####################################### Reporting bugs & Development Discussion ####################################### Please discuss this release on the samba-technical mailing list or by joining the #samba-technical IRC channel on irc.freenode.net. If you do report problems then please try to send high quality feedback. If you don't provide vital information to help us track down the problem then you will probably be ignored. All bug reports should be filed under the "Samba 4.1 and newer" product in the project's Bugzilla database (https://bugzilla.samba.org/). ======================================================================= Our Code, Our Bugs, Our Responsibility. == The Samba Team ===================================================================== ===============Download Details =============== The uncompressed tarballs and patch files have been signed using GnuPG (ID 6F33915B6568B7EA). The source code can be downloaded from: https://download.samba.org/pub/samba/stable/ The release notes are available online at: https://www.samba.org/samba/history/samba-4.10.8.html https://www.samba.org/samba/history/samba-4.9.13.html Our Code, Our Bugs, Our Responsibility. (https://bugzilla.samba.org/) --Enjoy The Samba Team -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 195 bytes Desc: not available URL: <http://lists.samba.org/pipermail/samba-announce/attachments/20190903/2b2c38af/signature.sig>
Seemingly Similar Threads
- [Announce] Samba 4.10.8 and 4.9.13 Security Releases Available
- [Announce] Samba 4.11.0rc3 Available for Download
- [Announce] Samba 4.11.0rc3 Available for Download
- [Announce] Samba 4.11.0 Available for Download
- [Announce] Samba 4.11.0 Available for Download