samba4: security bump to version 4.3.3
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Thu, 17 Dec 2015 10:59:18 +0000 (07:59 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Thu, 17 Dec 2015 11:56:30 +0000 (12:56 +0100)
Fixes:
CVE-2015-7540 - Remote DoS in Samba (AD) LDAP server
CVE-2015-3223 - Denial of service in Samba Active Directory server
CVE-2015-5252 - Insufficient symlink verification in smbd)
CVE-2015-5299 - Missing access control check in shadow copy code
CVE-2015-5296 - Samba client requesting encryption vulnerable to
downgrade attack
CVE-2015-8467 - Denial of service attack against Windows Active
Directory server
CVE-2015-5330 - Remote memory read in Samba LDAP server

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/samba4/samba4.hash
package/samba4/samba4.mk

index 2959e5ba1f8d33c8cd986c67a8c5a9565305ab97..494ad17dcd990854acba3c1998dde46fc71f19af 100644 (file)
@@ -1,2 +1,2 @@
 # Locally calculated after checking pgp signature
-sha256 61989195caadf0f6fb51ce6bed5e203e6146facc2c276a26ad41901ad9129a75        samba-4.3.2.tar.gz
+sha256 e62d21313acbb29e24b0b80aaf2b63fdd1ccce4cfb741f333deca95a1a3a70df        samba-4.3.3.tar.gz
index 388a40cf1b8dadd2510e836bb99b65410c14e01c..50a2692bf9412d9d5ab65cfbc647ee9281c194b7 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-SAMBA4_VERSION = 4.3.2
+SAMBA4_VERSION = 4.3.3
 SAMBA4_SITE = http://ftp.samba.org/pub/samba/stable
 SAMBA4_SOURCE = samba-$(SAMBA4_VERSION).tar.gz
 SAMBA4_INSTALL_STAGING = YES