]> rtime.felk.cvut.cz Git - coffee/buildroot.git/commit
package/samba4: security bump to version 4.5.12
authorBernd Kuhls <bernd.kuhls@t-online.de>
Thu, 13 Jul 2017 20:03:48 +0000 (22:03 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 19 Jul 2017 22:17:29 +0000 (00:17 +0200)
commitad3d9f8bd6e85f2ddbb03757dddc5b6ac0c6150b
tree4520416974218c34dfc19785d3b964e622cc5bf4
parentd8318535f0363dd6ae5e1b5a05a9dc5d456d21e1
package/samba4: security bump to version 4.5.12

Fixes CVE-2017-11103:

All versions of Samba from 4.0.0 onwards using embedded Heimdal
Kerberos are vulnerable to a man-in-the-middle attack impersonating
a trusted server, who may gain elevated access to the domain by
returning malicious replication or authorization data.

Samba binaries built against MIT Kerberos are not vulnerable.

https://www.samba.org/samba/history/samba-4.5.12.html

[Peter: add CVE info]
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit f97510659f914ee51c0f32e82664179a69ab17ba)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/samba4/samba4.hash
package/samba4/samba4.mk