Bug 41196

Summary: Regressions regarding NTLMSSP hardening of CVE-2016-2110 in Samba 4.3.7 (3.2)
Product: UCS Reporter: Arvid Requate <requate>
Component: Samba4Assignee: Arvid Requate <requate>
Status: CLOSED FIXED QA Contact: Felix Botner <botner>
Severity: normal    
Priority: P5 CC: gohmann
Version: UCS 3.2Flags: requate: Patch_Available+
Target Milestone: UCS 3.2-8-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: Bug Report What type of bug is this?: 5: Major Usability: Impairs usability in key scenarios
Who will be affected by this bug?: 3: Will affect average number of installed domains How will those affected feel about the bug?: 3: A User would likely not purchase the product
User Pain: 0.257 Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): Troubleshooting
Max CVSS v3 score:
Bug Depends on: 41195    
Bug Blocks: 41228    

Description Arvid Requate univentionstaff 2016-05-03 19:57:44 CEST
+++ This bug was initially created as a clone of Bug #41195 +++

Regressions regarding the NTLMSSP hardening of CVE-2016-2110 in Samba 4.3.7 have been fixed upstream:

* https://bugzilla.samba.org/show_bug.cgi?id=11849
* https://bugzilla.samba.org/show_bug.cgi?id=11852
* see also https://bugzilla.samba.org/show_bug.cgi?id=11889
Comment 1 Arvid Requate univentionstaff 2016-05-09 21:01:04 CEST
The package has been rebuilt with the upstream patches for:

* https://bugzilla.samba.org/show_bug.cgi?id=11849
* https://bugzilla.samba.org/show_bug.cgi?id=11852

Advisory: samba.yaml
Comment 2 Arvid Requate univentionstaff 2016-05-10 20:00:53 CEST
Rebuilt with additional patch https://bugzilla.samba.org/show_bug.cgi?id=11912
Comment 3 Felix Botner univentionstaff 2016-05-31 16:22:39 CEST
OK - yaml
OK - patch
OK - samba tests (join, password change, share access)
OK - ucs-test
Comment 4 Janek Walkenhorst univentionstaff 2016-06-01 16:12:08 CEST
<http://errata.software-univention.de/ucs/3.2/427.html>