From ad19766c1e5107cfad1c406c3a361678a485f39a Mon Sep 17 00:00:00 2001 From: Patrick J Volkerding Date: Wed, 27 Jul 2022 19:17:38 +0000 Subject: [PATCH] Wed Jul 27 19:17:38 UTC 2022 patches/packages/samba-4.15.9-x86_64-1_slack15.0.txz: Upgraded. This update fixes the following security issues: Samba AD users can bypass certain restrictions associated with changing passwords. Samba AD users can forge password change requests for any user. Samba AD users can crash the server process with an LDAP add or modify request. Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request. Server memory information leak via SMB1. For more information, see: https://www.samba.org/samba/security/CVE-2022-2031.html https://www.samba.org/samba/security/CVE-2022-32744.html https://www.samba.org/samba/security/CVE-2022-32745.html https://www.samba.org/samba/security/CVE-2022-32746.html https://www.samba.org/samba/security/CVE-2022-32742.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2031 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32744 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32745 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32746 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32742 (* Security fix *) --- ChangeLog.rss | 36 +++++++++++++++- ChangeLog.txt | 24 +++++++++++ FILELIST.TXT | 42 +++++++++---------- ...xt => samba-4.15.9-x86_64-1_slack15.0.txt} | 0 patches/source/samba/samba.url | 4 +- 5 files changed, 81 insertions(+), 25 deletions(-) rename patches/packages/{samba-4.15.7-x86_64-1_slack15.0.txt => samba-4.15.9-x86_64-1_slack15.0.txt} (100%) diff --git a/ChangeLog.rss b/ChangeLog.rss index d2fd6d8db..a9b3b8aad 100644 --- a/ChangeLog.rss +++ b/ChangeLog.rss @@ -11,9 +11,41 @@ Tracking Slackware development in git. en-us urn:uuid:c964f45e-6732-11e8-bbe5-107b4450212f - Mon, 25 Jul 2022 20:53:49 GMT - Tue, 26 Jul 2022 11:30:17 GMT + Wed, 27 Jul 2022 19:17:38 GMT + Thu, 28 Jul 2022 11:30:17 GMT maintain_current_git.sh v 1.17 + + Wed, 27 Jul 2022 19:17:38 GMT + Wed, 27 Jul 2022 19:17:38 GMT + https://git.slackware.nl/current/tag/?h=20220727191738 + 20220727191738 + + +patches/packages/samba-4.15.9-x86_64-1_slack15.0.txz: Upgraded. + This update fixes the following security issues: + Samba AD users can bypass certain restrictions associated with changing + passwords. + Samba AD users can forge password change requests for any user. + Samba AD users can crash the server process with an LDAP add or modify + request. + Samba AD users can induce a use-after-free in the server process with an + LDAP add or modify request. + Server memory information leak via SMB1. + For more information, see: + https://www.samba.org/samba/security/CVE-2022-2031.html + https://www.samba.org/samba/security/CVE-2022-32744.html + https://www.samba.org/samba/security/CVE-2022-32745.html + https://www.samba.org/samba/security/CVE-2022-32746.html + https://www.samba.org/samba/security/CVE-2022-32742.html + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2031 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32744 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32745 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32746 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32742 + (* Security fix *) + ]]> + + Mon, 25 Jul 2022 20:53:49 GMT Mon, 25 Jul 2022 20:53:49 GMT diff --git a/ChangeLog.txt b/ChangeLog.txt index 01aa7dbbb..6e667bf22 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,27 @@ +Wed Jul 27 19:17:38 UTC 2022 +patches/packages/samba-4.15.9-x86_64-1_slack15.0.txz: Upgraded. + This update fixes the following security issues: + Samba AD users can bypass certain restrictions associated with changing + passwords. + Samba AD users can forge password change requests for any user. + Samba AD users can crash the server process with an LDAP add or modify + request. + Samba AD users can induce a use-after-free in the server process with an + LDAP add or modify request. + Server memory information leak via SMB1. + For more information, see: + https://www.samba.org/samba/security/CVE-2022-2031.html + https://www.samba.org/samba/security/CVE-2022-32744.html + https://www.samba.org/samba/security/CVE-2022-32745.html + https://www.samba.org/samba/security/CVE-2022-32746.html + https://www.samba.org/samba/security/CVE-2022-32742.html + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2031 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32744 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32745 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32746 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32742 + (* Security fix *) ++--------------------------+ Mon Jul 25 20:53:49 UTC 2022 patches/packages/mozilla-firefox-91.12.0esr-x86_64-1_slack15.0.txz: Upgraded. This update contains security fixes and improvements. diff --git a/FILELIST.TXT b/FILELIST.TXT index 492c965aa..93bc908f1 100644 --- a/FILELIST.TXT +++ b/FILELIST.TXT @@ -1,20 +1,20 @@ -Mon Jul 25 20:57:15 UTC 2022 +Wed Jul 27 19:20:06 UTC 2022 Here is the file list for this directory. If you are using a mirror site and find missing or extra files in the disk subdirectories, please have the archive administrator refresh the mirror. -drwxr-xr-x 12 root root 4096 2022-07-25 20:53 . +drwxr-xr-x 12 root root 4096 2022-07-27 19:17 . -rw-r--r-- 1 root root 5767 2022-02-02 22:44 ./ANNOUNCE.15.0 -rw-r--r-- 1 root root 16609 2022-03-30 19:03 ./CHANGES_AND_HINTS.TXT --rw-r--r-- 1 root root 1144147 2022-07-21 18:15 ./CHECKSUMS.md5 --rw-r--r-- 1 root root 163 2022-07-21 18:15 ./CHECKSUMS.md5.asc +-rw-r--r-- 1 root root 1146328 2022-07-25 20:57 ./CHECKSUMS.md5 +-rw-r--r-- 1 root root 163 2022-07-25 20:57 ./CHECKSUMS.md5.asc -rw-r--r-- 1 root root 17976 1994-06-10 02:28 ./COPYING -rw-r--r-- 1 root root 35147 2007-06-30 04:21 ./COPYING3 -rw-r--r-- 1 root root 19573 2016-06-23 20:08 ./COPYRIGHT.TXT -rw-r--r-- 1 root root 616 2006-10-02 04:37 ./CRYPTO_NOTICE.TXT --rw-r--r-- 1 root root 1912558 2022-07-25 20:53 ./ChangeLog.txt +-rw-r--r-- 1 root root 1913800 2022-07-27 19:17 ./ChangeLog.txt drwxr-xr-x 3 root root 4096 2013-03-20 22:17 ./EFI drwxr-xr-x 2 root root 4096 2022-02-02 08:21 ./EFI/BOOT -rw-r--r-- 1 root root 1187840 2021-06-15 19:16 ./EFI/BOOT/bootx64.efi @@ -25,7 +25,7 @@ drwxr-xr-x 2 root root 4096 2022-02-02 08:21 ./EFI/BOOT -rwxr-xr-x 1 root root 2504 2019-07-05 18:54 ./EFI/BOOT/make-grub.sh -rw-r--r-- 1 root root 10722 2013-09-21 19:02 ./EFI/BOOT/osdetect.cfg -rw-r--r-- 1 root root 1273 2013-08-12 21:08 ./EFI/BOOT/tools.cfg --rw-r--r-- 1 root root 1493805 2022-07-21 18:15 ./FILELIST.TXT +-rw-r--r-- 1 root root 1496513 2022-07-25 20:57 ./FILELIST.TXT -rw-r--r-- 1 root root 1572 2012-08-29 18:27 ./GPG-KEY -rw-r--r-- 1 root root 864745 2022-02-02 08:25 ./PACKAGES.TXT -rw-r--r-- 1 root root 8034 2022-02-02 03:36 ./README.TXT @@ -737,13 +737,13 @@ drwxr-xr-x 2 root root 4096 2008-05-07 05:21 ./pasture/source/php/pear -rwxr-xr-x 1 root root 9448 2018-05-16 22:38 ./pasture/source/php/php.SlackBuild -rw-r--r-- 1 root root 775 2017-07-07 19:25 ./pasture/source/php/php.ini-development.diff.gz -rw-r--r-- 1 root root 830 2005-12-09 05:18 ./pasture/source/php/slack-desc -drwxr-xr-x 4 root root 4096 2022-07-25 20:57 ./patches --rw-r--r-- 1 root root 42884 2022-07-25 20:57 ./patches/CHECKSUMS.md5 --rw-r--r-- 1 root root 163 2022-07-25 20:57 ./patches/CHECKSUMS.md5.asc --rw-r--r-- 1 root root 57508 2022-07-25 20:57 ./patches/FILE_LIST --rw-r--r-- 1 root root 11166547 2022-07-25 20:57 ./patches/MANIFEST.bz2 --rw-r--r-- 1 root root 32090 2022-07-25 20:57 ./patches/PACKAGES.TXT -drwxr-xr-x 3 root root 16384 2022-07-25 20:57 ./patches/packages +drwxr-xr-x 4 root root 4096 2022-07-27 19:20 ./patches +-rw-r--r-- 1 root root 42884 2022-07-27 19:20 ./patches/CHECKSUMS.md5 +-rw-r--r-- 1 root root 163 2022-07-27 19:20 ./patches/CHECKSUMS.md5.asc +-rw-r--r-- 1 root root 57508 2022-07-27 19:20 ./patches/FILE_LIST +-rw-r--r-- 1 root root 11167185 2022-07-27 19:20 ./patches/MANIFEST.bz2 +-rw-r--r-- 1 root root 32090 2022-07-27 19:20 ./patches/PACKAGES.TXT +drwxr-xr-x 3 root root 16384 2022-07-27 19:19 ./patches/packages -rw-r--r-- 1 root root 327 2022-02-15 05:07 ./patches/packages/aaa_base-15.0-x86_64-4_slack15.0.txt -rw-r--r-- 1 root root 10716 2022-02-15 05:07 ./patches/packages/aaa_base-15.0-x86_64-4_slack15.0.txz -rw-r--r-- 1 root root 163 2022-02-15 05:07 ./patches/packages/aaa_base-15.0-x86_64-4_slack15.0.txz.asc @@ -859,9 +859,9 @@ drwxr-xr-x 2 root root 4096 2022-05-09 21:37 ./patches/packages/linux-5.15 -rw-r--r-- 1 root root 385 2022-04-13 18:19 ./patches/packages/ruby-3.0.4-x86_64-1_slack15.0.txt -rw-r--r-- 1 root root 7739784 2022-04-13 18:19 ./patches/packages/ruby-3.0.4-x86_64-1_slack15.0.txz -rw-r--r-- 1 root root 163 2022-04-13 18:19 ./patches/packages/ruby-3.0.4-x86_64-1_slack15.0.txz.asc --rw-r--r-- 1 root root 507 2022-05-02 18:14 ./patches/packages/samba-4.15.7-x86_64-1_slack15.0.txt --rw-r--r-- 1 root root 12955460 2022-05-02 18:14 ./patches/packages/samba-4.15.7-x86_64-1_slack15.0.txz --rw-r--r-- 1 root root 163 2022-05-02 18:14 ./patches/packages/samba-4.15.7-x86_64-1_slack15.0.txz.asc +-rw-r--r-- 1 root root 507 2022-07-27 18:55 ./patches/packages/samba-4.15.9-x86_64-1_slack15.0.txt +-rw-r--r-- 1 root root 12969160 2022-07-27 18:55 ./patches/packages/samba-4.15.9-x86_64-1_slack15.0.txz +-rw-r--r-- 1 root root 163 2022-07-27 18:55 ./patches/packages/samba-4.15.9-x86_64-1_slack15.0.txz.asc -rw-r--r-- 1 root root 392 2022-07-11 18:30 ./patches/packages/seamonkey-2.53.13-x86_64-1_slack15.0.txt -rw-r--r-- 1 root root 38050584 2022-07-11 18:30 ./patches/packages/seamonkey-2.53.13-x86_64-1_slack15.0.txz -rw-r--r-- 1 root root 163 2022-07-11 18:30 ./patches/packages/seamonkey-2.53.13-x86_64-1_slack15.0.txz.asc @@ -898,7 +898,7 @@ drwxr-xr-x 2 root root 4096 2022-05-09 21:37 ./patches/packages/linux-5.15 -rw-r--r-- 1 root root 388 2022-03-28 19:09 ./patches/packages/zlib-1.2.12-x86_64-1_slack15.0.txt -rw-r--r-- 1 root root 105204 2022-03-28 19:09 ./patches/packages/zlib-1.2.12-x86_64-1_slack15.0.txz -rw-r--r-- 1 root root 163 2022-03-28 19:09 ./patches/packages/zlib-1.2.12-x86_64-1_slack15.0.txz.asc -drwxr-xr-x 43 root root 4096 2022-07-25 20:50 ./patches/source +drwxr-xr-x 43 root root 4096 2022-07-27 19:13 ./patches/source drwxr-xr-x 2 root root 4096 2022-01-16 05:07 ./patches/source/aaa_base -rw-r--r-- 1 root root 11041 2022-02-15 04:49 ./patches/source/aaa_base/_aaa_base.tar.gz -rwxr-xr-x 1 root root 3894 2022-02-15 05:07 ./patches/source/aaa_base/aaa_base.SlackBuild @@ -1228,14 +1228,14 @@ drwxr-xr-x 2 root root 4096 2022-04-13 18:15 ./patches/source/ruby -rw-r--r-- 1 root root 15494036 2022-04-12 12:30 ./patches/source/ruby/ruby-3.0.4.tar.lz -rwxr-xr-x 1 root root 4817 2022-04-13 18:14 ./patches/source/ruby/ruby.SlackBuild -rw-r--r-- 1 root root 837 2019-03-13 16:43 ./patches/source/ruby/slack-desc -drwxr-xr-x 2 root root 4096 2022-05-02 18:05 ./patches/source/samba +drwxr-xr-x 2 root root 4096 2022-07-27 18:46 ./patches/source/samba -rw-r--r-- 1 root root 703 2016-06-13 04:19 ./patches/source/samba/doinst.sh.gz -rw-r--r-- 1 root root 940 2016-06-04 17:50 ./patches/source/samba/rc.samba --rw-r--r-- 1 root root 833 2022-04-26 14:37 ./patches/source/samba/samba-4.15.7.tar.asc --rw-r--r-- 1 root root 11886089 2022-04-26 14:37 ./patches/source/samba/samba-4.15.7.tar.lz +-rw-r--r-- 1 root root 833 2022-07-27 07:26 ./patches/source/samba/samba-4.15.9.tar.asc +-rw-r--r-- 1 root root 11897548 2022-07-27 07:25 ./patches/source/samba/samba-4.15.9.tar.lz -rwxr-xr-x 1 root root 7654 2022-05-02 18:04 ./patches/source/samba/samba.SlackBuild -rw-r--r-- 1 root root 227 2019-02-06 20:36 ./patches/source/samba/samba.libsmbclient.h.ffmpeg.compat.diff.gz --rw-r--r-- 1 root root 129 2022-05-02 18:04 ./patches/source/samba/samba.url +-rw-r--r-- 1 root root 129 2022-07-27 18:45 ./patches/source/samba/samba.url -rw-r--r-- 1 root root 960 2018-02-27 06:13 ./patches/source/samba/slack-desc -rw-r--r-- 1 root root 7921 2018-04-29 17:31 ./patches/source/samba/smb.conf.default -rw-r--r-- 1 root root 7933 2018-01-14 20:41 ./patches/source/samba/smb.conf.default.orig diff --git a/patches/packages/samba-4.15.7-x86_64-1_slack15.0.txt b/patches/packages/samba-4.15.9-x86_64-1_slack15.0.txt similarity index 100% rename from patches/packages/samba-4.15.7-x86_64-1_slack15.0.txt rename to patches/packages/samba-4.15.9-x86_64-1_slack15.0.txt diff --git a/patches/source/samba/samba.url b/patches/source/samba/samba.url index a49895f3d..ed45c0509 100644 --- a/patches/source/samba/samba.url +++ b/patches/source/samba/samba.url @@ -1,2 +1,2 @@ -https://download.samba.org/pub/samba/stable/samba-4.15.7.tar.gz -https://download.samba.org/pub/samba/stable/samba-4.15.7.tar.asc +https://download.samba.org/pub/samba/stable/samba-4.15.9.tar.gz +https://download.samba.org/pub/samba/stable/samba-4.15.9.tar.asc