Subject: CVS commit: pkgsrc/net/samba
To: None <pkgsrc-changes@netbsd.org>
From: Martti Kuparinen <martti@netbsd.org>
List: pkgsrc-changes
Date: 03/16/2003 09:57:48
Module Name:	pkgsrc
Committed By:	martti
Date:		Sun Mar 16 07:57:47 UTC 2003

Modified Files:
	pkgsrc/net/samba: Makefile Makefile.common distinfo
	pkgsrc/net/samba/patches: patch-aa patch-ab patch-ad patch-ar

Log Message:
Updated samba to 2.2.8

****************************************
* IMPORTANT: Security bugfix for Samba *
****************************************

The SuSE security audit team, in particular Sebastian Krahmer
<krahmer@suse.de>, has found a flaw in the Samba main smbd code which
could allow an external attacker to remotely and anonymously gain
Super User (root) privileges on a server running a Samba server.

This flaw exists in previous versions of Samba from 2.0.x to 2.2.7a
inclusive.  This is a serious problem and all sites should either
upgrade to Samba 2.2.8 immediately or prohibit access to TCP ports 139
and 445. Advice created by Andrew Tridgell, the leader of the Samba
Team, on how to protect an unpatched Samba server is given at the end
of this section.

The SMB/CIFS protocol implemented by Samba is vulnerable to many
attacks, even without specific security holes.  The TCP ports 139 and
the new port 445 (used by Win2k and the Samba 3.0 alpha code in
particular) should never be exposed to untrusted networks.


To generate a diff of this commit:
cvs rdiff -r1.94 -r1.95 pkgsrc/net/samba/Makefile
cvs rdiff -r1.5 -r1.6 pkgsrc/net/samba/Makefile.common
cvs rdiff -r1.26 -r1.27 pkgsrc/net/samba/distinfo
cvs rdiff -r1.23 -r1.24 pkgsrc/net/samba/patches/patch-aa
cvs rdiff -r1.19 -r1.20 pkgsrc/net/samba/patches/patch-ab
cvs rdiff -r1.11 -r1.12 pkgsrc/net/samba/patches/patch-ad
cvs rdiff -r1.1 -r1.2 pkgsrc/net/samba/patches/patch-ar

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.