Bug 41228 - Regressions regarding NTLMSSP hardening of CVE-2016-2110 in Samba 4.3.7 (ES 3.1)
Regressions regarding NTLMSSP hardening of CVE-2016-2110 in Samba 4.3.7 (ES 3.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Samba
UCS 3.1
Other Linux
: P5 normal (vote)
: UCS 3.1-ES
Assigned To: Arvid Requate
Felix Botner
:
Depends on: 41196
Blocks:
  Show dependency treegraph
 
Reported: 2016-05-09 19:16 CEST by Arvid Requate
Modified: 2016-09-29 17:31 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 5: Major Usability: Impairs usability in key scenarios
Who will be affected by this bug?: 4: Will affect most installed domains
How will those affected feel about the bug?: 3: A User would likely not purchase the product
User Pain: 0.343
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Troubleshooting
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2016-05-09 19:16:49 CEST
+++ This bug was initially created as a clone of Bug #41196 +++

Regressions regarding the NTLMSSP hardening of CVE-2016-2110 in Samba 4.3.7 have been fixed upstream:

* https://bugzilla.samba.org/show_bug.cgi?id=11849
* https://bugzilla.samba.org/show_bug.cgi?id=11852
* see also https://bugzilla.samba.org/show_bug.cgi?id=11889
Comment 1 Arvid Requate univentionstaff 2016-05-09 21:01:00 CEST
The package has been rebuilt with the upstream patches for:

* https://bugzilla.samba.org/show_bug.cgi?id=11849
* https://bugzilla.samba.org/show_bug.cgi?id=11852

Version: 2:4.3.7-1.826.201605091947
Comment 2 Arvid Requate univentionstaff 2016-05-10 13:58:49 CEST
Rebuilt with additional patch https://bugzilla.samba.org/show_bug.cgi?id=11912

Version: 2:4.3.7-1.826.201605101131
Comment 3 Arvid Requate univentionstaff 2016-05-19 18:37:15 CEST
Rebuilt with additional patches:
  https://bugzilla.samba.org/show_bug.cgi?id=11744#c43

Version: 2:4.3.7-1.826.201605191435
Comment 4 Felix Botner univentionstaff 2016-06-02 12:26:39 CEST
FAIL - please add a txt file for samba to ucs-3.1/ucs-3.1-1/doc/errata/staging

OK - 2:4.3.7-1.826.201605191435
OK - update 
     * basic tests (smbclient, slave join, windows join, share access)
     * ucs-test 
     * update to 3.2
OK - installation
     * basic tests (smbclient, slave join, windows join, share access, password 
       change)
     * update to 3.2
Comment 5 Arvid Requate univentionstaff 2016-06-07 13:22:32 CEST
Advisory: samba.txt
Comment 6 Janek Walkenhorst univentionstaff 2016-06-20 17:42:00 CEST
<http://errata.software-univention.de/ucs/3.1/286.html>