[Announce] Samba 4.10.8 and 4.9.13 Security Releases Available
Karolin Seeger
kseeger at samba.org
Tue Sep 3 07:31:06 UTC 2019
Release Announcements
---------------------
These are a security releases in order to address the following defect:
o CVE-2019-10197: Combination of parameters and permissions can allow user
to escape from the share path definition.
=======
Details
=======
o CVE-2019-10197:
Under certain parameter configurations, when an SMB client accesses a network
share and the user does not have permission to access the share root
directory, it is possible for the user to escape from the share to see the
complete '/' filesystem. Unix permission checks in the kernel are still
enforced.
Changes:
--------
o Jeremy Allison <jra at samba.org>
* BUG 14035: CVE-2019-10197: Permissions check deny can allow user to escape
from the share.
o Stefan Metzmacher <metze at samba.org>
* BUG 14035: CVE-2019-10197: Permissions check deny can allow user to escape
from the share.
#######################################
Reporting bugs & Development Discussion
#######################################
Please discuss this release on the samba-technical mailing list or by
joining the #samba-technical IRC channel on irc.freenode.net.
If you do report problems then please try to send high quality
feedback. If you don't provide vital information to help us track down
the problem then you will probably be ignored. All bug reports should
be filed under the "Samba 4.1 and newer" product in the project's Bugzilla
database (https://bugzilla.samba.org/).
======================================================================
== Our Code, Our Bugs, Our Responsibility.
== The Samba Team
======================================================================
================
Download Details
================
The uncompressed tarballs and patch files have been signed
using GnuPG (ID 6F33915B6568B7EA). The source code can be downloaded
from:
https://download.samba.org/pub/samba/stable/
The release notes are available online at:
https://www.samba.org/samba/history/samba-4.10.8.html
https://www.samba.org/samba/history/samba-4.9.13.html
Our Code, Our Bugs, Our Responsibility.
(https://bugzilla.samba.org/)
--Enjoy
The Samba Team
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba-announce/attachments/20190903/2b2c38af/signature.sig>
More information about the samba-announce
mailing list