[Announce] Samba 3.3.6 Security Release Available for Download
Karolin Seeger <[email protected]> Tue, 23 Jun 2009 16:43:51 +0200
| Newsgroups | gmane.network.samba.announce |
|---|---|
| Organization | SerNet GmbH, Goettingen, Germany |
| Message-ID | <E1MJ7E2-00DGIZ-Oa__45698.1727890254$1245769200$gmane$org@intern.SerNet.DE> |
Release Announcements
=====================
This is a security release in order to address CVE-2009-1888.
o CVE-2009-1888:
In Samba 3.0.31 to 3.3.5 (inclusive), an uninitialized read of a
data value can potentially affect access control when "dos filemode"
is set to "yes".
######################################################################
Changes
#######
Changes since 3.3.5:
--------------------
o Jeremy Allison <[email protected]>
* BUG 6488: Fix for CVE-2009-1888.
================
Download Details
================
The uncompressed tarballs and patch files have been signed
using GnuPG (ID 6568B7EA). The source code can be downloaded
from:
http://download.samba.org/samba/ftp/
The release notes are available online at:
http://www.samba.org/samba/ftp/history/samba-3.3.6.html
Binary packages will be made available on a volunteer basis from
http://download.samba.org/samba/ftp/Binary_Packages/
Our Code, Our Bugs, Our Responsibility.
(https://bugzilla.samba.org/)
--Enjoy
The Samba Team
signature.asc
(application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (GNU/Linux) iEYEARECAAYFAkpA6icACgkQKGi9fisXk1FdHgCglhMttmHTCjw5o4gl5w5FJ28b W1oAmgM1VDVhkUGiCNDIxiSufl+dI3AE =PTdy -----END PGP SIGNATURE-----