Univention Bugzilla – Bug 41012
samba: multiple issues (ES 3.1)
Last modified: 2016-05-19 18:41:38 CEST
Samba 4.2.10 (and 4.3.7) fixes a couple of security issues.
Created attachment 7583 [details] ES31-bug41012-advisories-draft.tar.bz2 Advisory drafts.
Done: • for p in talloc tevent tdb ldb samba; do repo_admin.py --cherrypick --release 4.1-0 --source errata4.1-1 \ --releasedest 3.2-0 --dest errata3.2-8 --package $p; b32-scope errata3.2-8 $p done • univention-ldb-modules not rebuilt (No UCS@school for extsec3.1) • Selective backport from errata3.2-8 for: univention-samba univention-samba4 univention-s4-connector Current version matrix: talloc: 2.1.5-1.37.201604061642: ucs_3.1-0-extsec3.1 2.1.5-1.38.201604061644: ucs_3.2-0-errata3.2-8 2.1.5-1.39.201604061650: ucs_3.3-0 2.1.5-1.40.201604061653: ucs_4.0-0-errata4.0-5 2.1.5-1.41.201512111354: ucs_4.1-0-errata4.1-0 # no update tevent: 0.9.26-1.29.201604061703: ucs_3.1-0-extsec3.1 0.9.26-1.30.201604061703: ucs_3.2-0-errata3.2-8 0.9.26-1.31.201604061703: ucs_3.3-0 0.9.26-1.32.201604061703: ucs_4.0-0-errata4.0-5 0.9.26-1.33.201512111415: ucs_4.1-0-errata4.1-0 # no update tdb: 1.3.8-1.50.201604061726: ucs_3.1-0-extsec3.1 1.3.8-1.51.201604061726: ucs_3.2-0-errata3.2-8 1.3.8-1.52.201604061744: ucs_3.3-0 1.3.8-1.53.201604061726: ucs_4.0-0-errata4.0-5 1.3.8-1.54.201512111342: ucs_4.1-0-errata4.1-0 # no update ldb: Version: 2:1.1.25-1.68.201604061731: ucs_3.1-0-extsec3.1 Version: 2:1.1.25-1.69.201604061731: ucs_3.2-0-errata3.2-8 Version: 2:1.1.25-1.70.201604061731: ucs_3.3-0 Version: 2:1.1.25-1.71.201604061731: ucs_4.0-0-errata4.0-5 Version: 2:1.1.25-1.72.201604061731: ucs_4.1-0-errata4.1-1 samba: Version: 2:4.3.7-1.826.201604061853: ucs_3.1-0-extsec3.1 Version: 2:4.3.7-1.827.201604061853: ucs_3.2-0-errata3.2-8 Version: 2:4.3.6-1.874.201604011331: ucs_3.3-0 ## TODO Version: 2:4.3.7-1.829.201604062049: ucs_4.0-0-errata4.0-5 Version: 2:4.3.7-1.830.201604062051: ucs_4.1-0-errata4.1-1
Resolved for final QA and release stage.
Tests, see http://bladis.knut.univention.de/71iBVhOsGa OK - Install OK - Update OK - 3.1-ldb.txt OK - 3.1-samba.txt OK - 3.1-talloc.txt OK - 3.1-tdb.txt OK - 3.1-tevent.txt OK - 3.1-univention-s4-connector.txt OK - 3.1-univention-samba4.txt OK - 3.1-univention-samba.txt
Released
Created attachment 7591 [details] ES31-bug41012-advisories.tar.bz2
Fixes: CVE-2015-5370 CVE-2016-2110 CVE-2016-2111 CVE-2016-2112 CVE-2016-2113 CVE-2016-2114 CVE-2016-2115 CVE-2016-2118
*** Bug 40921 has been marked as a duplicate of this bug. ***