pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/net/samba35



Module Name:    pkgsrc
Committed By:   taca
Date:           Wed Jul 27 00:52:20 UTC 2011

Modified Files:
        pkgsrc/net/samba35: Makefile distinfo

Log Message:
Update samba35 pacakge to 3.5.10; security fix for swat.

                   ==============================
                   Release Notes for Samba 3.5.10
                           July 26, 2011
                   ==============================

This is a security release in order to address
CVE-2011-2522 (Cross-Site Request Forgery in SWAT) and
CVE-2011-2694 (Cross-Site Scripting vulnerability in SWAT).

o  CVE-2011-2522:
   The Samba Web Administration Tool (SWAT) in Samba versions
   3.0.x to 3.5.9 are affected by a cross-site request forgery.

o  CVE-2011-2694:
   The Samba Web Administration Tool (SWAT) in Samba versions
   3.0.x to 3.5.9 are affected by a cross-site scripting
   vulnerability.

Please note that SWAT must be enabled in order for these
vulnerabilities to be exploitable. By default, SWAT
is *not* enabled on a Samba install.

Changes since 3.5.9:
--------------------

o   Kai Blin <kai%samba.org@localhost>
    * BUG 8289: SWAT contains a cross-site scripting vulnerability.
    * BUG 8290: CSRF vulnerability in SWAT.


To generate a diff of this commit:
cvs rdiff -u -r1.7 -r1.8 pkgsrc/net/samba35/Makefile
cvs rdiff -u -r1.4 -r1.5 pkgsrc/net/samba35/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.



Home | Main Index | Thread Index | Old Index