samba4: security bump to version 4.3.6
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 8 Mar 2016 21:31:20 +0000 (18:31 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 8 Mar 2016 21:33:23 +0000 (22:33 +0100)
Fixes:
CVE-2015-7560 - Authenticated client could cause Samba to overwrite ACLs
with incorrect owner/group.
CVE-2016-0771 - Malicious request can cause the Samba internal DNS
server to crash or unintentionally return uninitialized memory.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/samba4/samba4.hash
package/samba4/samba4.mk

index 1b536577da66bdc69a4f2f6dcf4eb2dd77e32fba..d8458e6cd498b1fbea7fda0ca8b0667609451faa 100644 (file)
@@ -1,2 +1,2 @@
 # Locally calculated after checking pgp signature
-sha256 583f927a823b272757fd4df0be267bd20a223b06cfc3c662df17e4870f14bf1c        samba-4.3.5.tar.gz
+sha256 3251eca5b196854e79978f4a92d5fd2b55bd7b0a252a65131a9be02be6754924        samba-4.3.6.tar.gz
index 715983e6e11d30702aca31f5d6e8259b9537883c..ee0452e6c232d85cffe67d441421f46e45f51e5e 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-SAMBA4_VERSION = 4.3.5
+SAMBA4_VERSION = 4.3.6
 SAMBA4_SITE = http://ftp.samba.org/pub/samba/stable
 SAMBA4_SOURCE = samba-$(SAMBA4_VERSION).tar.gz
 SAMBA4_INSTALL_STAGING = YES