[Buildroot] [PATCH] samba4: security bump to version 4.6.11

Peter Korsgaard peter at korsgaard.com
Mon Nov 27 09:46:35 UTC 2017


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issues:
 >  - CVE-2017-14746:
 >    All versions of Samba from 4.0.0 onwards are vulnerable to a use after
 >    free vulnerability, where a malicious SMB1 request can be used to
 >    control the contents of heap memory via a deallocated heap pointer. It
 >    is possible this may be used to compromise the SMB server.

 >  - CVE-2017-15275:
 >    All versions of Samba from 3.6.0 onwards are vulnerable to a heap
 >    memory information leak, where server allocated heap memory may be
 >    returned to the client without being cleared.

 >    There is no known vulnerability associated with this error, but
 >    uncleared heap memory may contain previously used data that may help
 >    an attacker compromise the server via other methods. Uncleared heap
 >    memory may potentially contain password hashes or other high-value
 >    data.

 > For more details, see the release notes:
 > https://www.samba.org/samba/history/samba-4.6.11.html

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2017.08.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list