From 2b4ffc9571c637212347354378447f26941d8f73 Mon Sep 17 00:00:00 2001 From: jca Date: Wed, 30 Oct 2019 12:20:48 +0000 Subject: [PATCH] SECURITY update to samba-4.9.15 Fixes for: o CVE-2019-10218: Client code can return filenames containing path separators. o CVE-2019-14833: Samba AD DC check password script does not receive the full password. o CVE-2019-14847: User with "get changes" permission can crash AD DC LDAP server via dirsync. Release notes for 4.9.14 and 4.9.15: https://www.samba.org/samba/history/samba-4.9.14.html https://www.samba.org/samba/history/samba-4.9.15.html Tested by and ok gonzalo@ --- net/samba/Makefile | 10 ++++++---- net/samba/distinfo | 4 ++-- net/samba/pkg/PLIST-main | 5 ++++- 3 files changed, 12 insertions(+), 7 deletions(-) diff --git a/net/samba/Makefile b/net/samba/Makefile index 511cd3575a0..7424ad71d65 100644 --- a/net/samba/Makefile +++ b/net/samba/Makefile @@ -1,6 +1,6 @@ -# $OpenBSD: Makefile,v 1.277 2019/10/07 13:35:48 jca Exp $ +# $OpenBSD: Makefile,v 1.278 2019/10/30 12:20:48 jca Exp $ -VERSION = 4.9.13 +VERSION = 4.9.15 DISTNAME = samba-${VERSION} COMMENT-main = SMB and CIFS client and server for UNIX @@ -17,9 +17,11 @@ PKGNAME-docs = samba-docs-${VERSION} PKG_ARCH-docs = * -LDB_V = 1.4.7 +LDB_V = 1.4.8 TEVENT_V = 0.9.37 +REVISION-tevent = 0 + SHARED_LIBS = asn1-samba4 0.0 \ com_err-samba4 0.0 \ dcerpc 0.0 \ @@ -34,7 +36,7 @@ SHARED_LIBS = asn1-samba4 0.0 \ hx509-samba4 0.0 \ kdc-samba4 0.0 \ krb5-samba4 0.1 \ - ldb 0.8 \ + ldb 0.9 \ ndr 0.3 \ ndr-krb5pac 0.1 \ ndr-nbt 0.1 \ diff --git a/net/samba/distinfo b/net/samba/distinfo index 4292085128a..0f32aba99e1 100644 --- a/net/samba/distinfo +++ b/net/samba/distinfo @@ -1,2 +1,2 @@ -SHA256 (samba-4.9.13.tar.gz) = qxgzHjd2axPbsH0fEVvaPXlJF7r1AtDKKyuP/wFLiPI= -SIZE (samba-4.9.13.tar.gz) = 18109481 +SHA256 (samba-4.9.15.tar.gz) = N3ECuAuXlBvw0TG4KMroQVGQ5b3SkowuLJVOKfGQRJY= +SIZE (samba-4.9.15.tar.gz) = 18110369 diff --git a/net/samba/pkg/PLIST-main b/net/samba/pkg/PLIST-main index 0201fb3af3e..841fd1bec91 100644 --- a/net/samba/pkg/PLIST-main +++ b/net/samba/pkg/PLIST-main @@ -1,4 +1,4 @@ -@comment $OpenBSD: PLIST-main,v 1.50 2019/10/07 12:50:14 jca Exp $ +@comment $OpenBSD: PLIST-main,v 1.51 2019/10/30 12:20:48 jca Exp $ @conflict ldb-<1.3.6p5 @pkgpath net/samba,ldap,-main @pkgpath net/samba,ads,-main @@ -535,6 +535,9 @@ lib/python${MODPY_VERSION}/site-packages/samba/tests/blackbox/traffic_replay.${M lib/python${MODPY_VERSION}/site-packages/samba/tests/blackbox/traffic_summary.py lib/python${MODPY_VERSION}/site-packages/samba/tests/blackbox/traffic_summary.pyc lib/python${MODPY_VERSION}/site-packages/samba/tests/blackbox/traffic_summary.${MODPY_PYOEXTENSION} +lib/python${MODPY_VERSION}/site-packages/samba/tests/blackbox/undoguididx.py +lib/python${MODPY_VERSION}/site-packages/samba/tests/blackbox/undoguididx.pyc +lib/python${MODPY_VERSION}/site-packages/samba/tests/blackbox/undoguididx.${MODPY_PYOEXTENSION} lib/python${MODPY_VERSION}/site-packages/samba/tests/common.py lib/python${MODPY_VERSION}/site-packages/samba/tests/common.pyc lib/python${MODPY_VERSION}/site-packages/samba/tests/common.${MODPY_PYOEXTENSION}