Bug 41195

Summary: Regressions regarding NTLMSSP hardening of CVE-2016-2110 in Samba 4.3.7 (3.3)
Product: UCS Reporter: Arvid Requate <requate>
Component: Samba4Assignee: Arvid Requate <requate>
Status: CLOSED FIXED QA Contact: Felix Botner <botner>
Severity: normal    
Priority: P5 Flags: requate: Patch_Available+
Version: UCS 3.3   
Target Milestone: UCS 3.3   
Hardware: Other   
OS: Linux   
What kind of report is it?: Development Internal What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): Troubleshooting
Max CVSS v3 score:
Bug Depends on: 41194    
Bug Blocks: 41196    

Description Arvid Requate univentionstaff 2016-05-03 19:56:51 CEST
+++ This bug was initially created as a clone of Bug #41194 +++

Regressions regarding the NTLMSSP hardening of CVE-2016-2110 in Samba 4.3.7 have been fixed upstream:

* https://bugzilla.samba.org/show_bug.cgi?id=11849
* https://bugzilla.samba.org/show_bug.cgi?id=11852
* see also https://bugzilla.samba.org/show_bug.cgi?id=11889
Comment 1 Arvid Requate univentionstaff 2016-05-09 21:00:47 CEST
The package has been rebuilt with the upstream patches for:

* https://bugzilla.samba.org/show_bug.cgi?id=11849
* https://bugzilla.samba.org/show_bug.cgi?id=11852

Version: 2:4.3.7-1.828.201605092038
Comment 2 Arvid Requate univentionstaff 2016-05-10 14:31:14 CEST
Rebuilt with additional patch https://bugzilla.samba.org/show_bug.cgi?id=11912

Version: 2:4.3.7-1.828.201605101154
Comment 3 Arvid Requate univentionstaff 2016-05-19 18:35:56 CEST
Rebuilt with additional patches:
  https://bugzilla.samba.org/show_bug.cgi?id=11744#c43

Version: 2:4.3.7-1.828.201605191457
Comment 4 Felix Botner univentionstaff 2016-05-23 17:24:25 CEST
OK - ucs-test
OK - manual test (windows join, password change, share access)
OK - version 2:4.3.7-1.828.201605191457
Comment 5 Stefan Gohmann univentionstaff 2016-06-07 21:35:48 CEST
UCS 3.3 has been released:
 https://docs.software-univention.de/release-notes-3.3-0-en.html
 https://docs.software-univention.de/release-notes-3.3-0-de.html

If this error occurs again, please use "Clone This Bug".