Displaying 20 results from an estimated 8000 matches similar to: "[Announce] Samba meta-data symlink vulnerability CVE-2021-20316"
2021 Nov 09
2
[Announce] Samba 4.15.2, 4.14.10, 4.13.14 Security Releases are available for Download
Release Announcements
---------------------
These are security releases in order to address the following defects:
o CVE-2016-2124: SMB1 client connections can be downgraded to plaintext
authentication.
https://www.samba.org/samba/security/CVE-2016-2124.html
o CVE-2020-25717: A user on the domain can become root on domain members.
2021 Nov 09
2
[Announce] Samba 4.15.2, 4.14.10, 4.13.14 Security Releases are available for Download
Release Announcements
---------------------
These are security releases in order to address the following defects:
o CVE-2016-2124: SMB1 client connections can be downgraded to plaintext
authentication.
https://www.samba.org/samba/security/CVE-2016-2124.html
o CVE-2020-25717: A user on the domain can become root on domain members.
2021 Jun 21
1
CVE-2021-33515: SMTP Submission service STARTTLS injection
Open-Xchange Security Advisory 2021-06-21
Product: Dovecot
Vendor: OX Software GmbH
Internal reference: DOV-4583 (Bug ID)
Vulnerability type: CWE-74: Failure to Sanitize Data into a Different Plane ('Injection')
Vulnerable version: 2.3.0-2.3.14
Vulnerable component: submission
Report confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 2.3.14.1
Vendor notification:
2021 Jun 21
1
CVE-2021-33515: SMTP Submission service STARTTLS injection
Open-Xchange Security Advisory 2021-06-21
Product: Dovecot
Vendor: OX Software GmbH
Internal reference: DOV-4583 (Bug ID)
Vulnerability type: CWE-74: Failure to Sanitize Data into a Different Plane ('Injection')
Vulnerable version: 2.3.0-2.3.14
Vulnerable component: submission
Report confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 2.3.14.1
Vendor notification:
2021 Jun 21
0
CVE-2021-29157: oauth2 JWT local validation path traversal
Open-Xchange Security Advisory 2021-06-21
Product: Dovecot
Vendor: OX Software GmbH
Internal reference: DOV-4476 (Bug ID)
Vulnerability type: CWE-24: Path Traversal: '../filedir'
Vulnerable version: 2.3.11-2.3.14
Vulnerable component: imap, pop3, submission, managesieve
Report confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 2.3.14.1
Vendor notification: 2021-03-22
2021 Jun 21
0
CVE-2021-29157: oauth2 JWT local validation path traversal
Open-Xchange Security Advisory 2021-06-21
Product: Dovecot
Vendor: OX Software GmbH
Internal reference: DOV-4476 (Bug ID)
Vulnerability type: CWE-24: Path Traversal: '../filedir'
Vulnerable version: 2.3.11-2.3.14
Vulnerable component: imap, pop3, submission, managesieve
Report confidence: Confirmed
Solution status: Fixed by Vendor
Fixed version: 2.3.14.1
Vendor notification: 2021-03-22
2022 Feb 15
0
[Announce] Samba 4.16.0rc3 Available for Download
Release Announcements
=====================
This is the third release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Feb 15
0
[Announce] Samba 4.16.0rc3 Available for Download
Release Announcements
=====================
This is the third release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Mar 01
0
[Announce] Samba 4.16.0rc4 Available for Download
Release Announcements
=====================
This is the fourth release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Mar 01
0
[Announce] Samba 4.16.0rc4 Available for Download
Release Announcements
=====================
This is the fourth release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Mar 08
0
[Announce] Samba 4.16.0rc5 Available for Download
Release Announcements
=====================
This is the fifth release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Mar 08
0
[Announce] Samba 4.16.0rc5 Available for Download
Release Announcements
=====================
This is the fifth release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Jan 10
0
[Announce] Samba 4.13.16 Security Release is available for Download
Release Announcements
---------------------
This is a security release in order to address the following defects:
o CVE-2021-43566:? mkdir race condition allows share escape in Samba 4.x.
https://www.samba.org/samba/security/CVE-2021-43566.html
=======
Details
=======
o? CVE-2021-43566:
?? All versions of Samba prior to 4.13.16 are vulnerable to a malicious
?? client using an SMB1 or NFS
2022 Jan 10
0
[Announce] Samba 4.13.16 Security Release is available for Download
Release Announcements
---------------------
This is a security release in order to address the following defects:
o CVE-2021-43566:? mkdir race condition allows share escape in Samba 4.x.
https://www.samba.org/samba/security/CVE-2021-43566.html
=======
Details
=======
o? CVE-2021-43566:
?? All versions of Samba prior to 4.13.16 are vulnerable to a malicious
?? client using an SMB1 or NFS
2022 Jan 31
1
[Announce] Samba 4.16.0rc2 Available for Download
Release Announcements
=====================
This is the second release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Jan 31
1
[Announce] Samba 4.16.0rc2 Available for Download
Release Announcements
=====================
This is the second release candidate of Samba 4.16.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.16 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Sep 13
0
[Announce] Samba 4.17.0 Available for Download
Release Announcements
---------------------
This is the first stable release of the Samba 4.17 release series.
Please read the release notes carefully before upgrading.
NEW FEATURES/CHANGES
====================
SMB Server performance improvements
-----------------------------------
The security improvements in recent releases
(4.13, 4.14, 4.15, 4.16), mainly as protection against symlink
2022 Sep 13
0
[Announce] Samba 4.17.0 Available for Download
Release Announcements
---------------------
This is the first stable release of the Samba 4.17 release series.
Please read the release notes carefully before upgrading.
NEW FEATURES/CHANGES
====================
SMB Server performance improvements
-----------------------------------
The security improvements in recent releases
(4.13, 4.14, 4.15, 4.16), mainly as protection against symlink
2022 Sep 06
0
[Announce] Samba 4.17.0rc5 Available for Download
Release Announcements
=====================
This is the fifth release candidate of Samba 4.17.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.17 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES
2022 Sep 06
0
[Announce] Samba 4.17.0rc5 Available for Download
Release Announcements
=====================
This is the fifth release candidate of Samba 4.17.? This is *not*
intended for production environments and is designed for testing
purposes only.? Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
Samba 4.17 will be the next version of the Samba suite.
UPGRADING
=========
NEW FEATURES/CHANGES