From 759a12e5e6d00eb8da581eccdc4306dcfe7bec2b Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Thu, 30 Nov 2023 21:21:55 +0000 Subject: Thu Nov 30 21:21:55 UTC 2023 patches/packages/samba-4.18.9-x86_64-1_slack15.0.txz: Upgraded. This is a security release in order to address the following defect: An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store. Upgrading to this package will not prevent this information leak - if you are using Samba as an Active Directory Domain Controller, you will need to follow the instructions in the samba.org link given below. For more information, see: https://www.samba.org/samba/security/CVE-2018-14628.html https://www.cve.org/CVERecord?id=CVE-2018-14628 (* Security fix *) --- ChangeLog.rss | 27 +++++++++++++++++++++++++-- 1 file changed, 25 insertions(+), 2 deletions(-) (limited to 'ChangeLog.rss') diff --git a/ChangeLog.rss b/ChangeLog.rss index e4e92d0b0..2a7609cdd 100644 --- a/ChangeLog.rss +++ b/ChangeLog.rss @@ -11,9 +11,32 @@ Tracking Slackware development in git. en-us urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f - Tue, 28 Nov 2023 22:13:48 GMT - Wed, 29 Nov 2023 12:30:28 GMT + Thu, 30 Nov 2023 21:21:55 GMT + Fri, 1 Dec 2023 12:30:24 GMT maintain_current_git.sh v 1.17 + + Thu, 30 Nov 2023 21:21:55 GMT + Thu, 30 Nov 2023 21:21:55 GMT + https://git.slackware.nl/current/tag/?h=20231130212155 + 20231130212155 + + +patches/packages/samba-4.18.9-x86_64-1_slack15.0.txz: Upgraded. + This is a security release in order to address the following defect: + An information leak vulnerability was discovered in Samba's LDAP server. + Due to missing access control checks, an authenticated but unprivileged + attacker could discover the names and preserved attributes of deleted objects + in the LDAP store. Upgrading to this package will not prevent this + information leak - if you are using Samba as an Active Directory Domain + Controller, you will need to follow the instructions in the samba.org link + given below. + For more information, see: + https://www.samba.org/samba/security/CVE-2018-14628.html + https://www.cve.org/CVERecord?id=CVE-2018-14628 + (* Security fix *) + ]]> + + Tue, 28 Nov 2023 22:13:48 GMT Tue, 28 Nov 2023 22:13:48 GMT -- cgit v1.2.3-65-gdbad