summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authortron <tron>2015-03-04 20:00:15 +0000
committertron <tron>2015-03-04 20:00:15 +0000
commit06f080ea1b9f08df33c03176f6af483b9efd3da8 (patch)
treeb9c5df6933377eafbec8d45ac15001ba8008db77
parentb2d3cc614a8e95ce7c9499213acf70605e52e950 (diff)
downloadpkgsrc-06f080ea1b9f08df33c03176f6af483b9efd3da8.tar.gz
Pullup ticket #4634 - requested by taca
net/samba: security update Revisions pulled up: - net/samba/Makefile 1.253 - net/samba/distinfo 1.102 --- Module Name: pkgsrc Committed By: taca Date: Tue Feb 24 09:54:47 UTC 2015 Modified Files: pkgsrc/net/samba: Makefile distinfo Log Message: Update samba package to 3.6.25. ============================== Release Notes for Samba 3.6.25 February 23, 2015 ============================== This is a security release in order to address CVE-2015-0240 (Unexpected code execution in smbd). o CVE-2015-0240: All versions of Samba from 3.5.0 to 4.2.0rc4 are vulnerable to an unexpected code execution vulnerability in the smbd file server daemon. A malicious client could send packets that may set up the stack in such a way that the freeing of memory in a subsequent anonymous netlogon packet could allow execution of arbitrary code. This code would execute with root privileges. o CVE-2014-0178: In preparing a response to an authenticated FSCTL_GET_SHADOW_COPY_DATA or FSCTL_SRV_ENUMERATE_SNAPSHOTS client request, affected versions of Samba do not initialize 8 bytes of the 16 byte SRV_SNAPSHOT_ARRAY response field. The uninitialized buffer is sent back to the client. A non-default VFS module providing the get_shadow_copy_data_fn() hook must be explicitly enabled for Samba to process the aforementioned client requests. Therefore, only configurations with "shadow_copy" or "shadow_copy2" specified for the "vfs objects" parameter are vulnerable.
-rw-r--r--net/samba/Makefile4
-rw-r--r--net/samba/distinfo8
2 files changed, 6 insertions, 6 deletions
diff --git a/net/samba/Makefile b/net/samba/Makefile
index 2b46e8cdadc..b30ae832f54 100644
--- a/net/samba/Makefile
+++ b/net/samba/Makefile
@@ -1,4 +1,4 @@
-# $NetBSD: Makefile,v 1.252 2014/07/21 06:44:30 obache Exp $
+# $NetBSD: Makefile,v 1.252.4.1 2015/03/04 20:00:15 tron Exp $
DISTNAME= samba-${VERSION}
CATEGORIES= net
@@ -9,7 +9,7 @@ HOMEPAGE= http://www.samba.org/
COMMENT= SMB/CIFS protocol server suite
LICENSE= gnu-gpl-v3
-VERSION= 3.6.24
+VERSION= 3.6.25
CONFLICTS+= ja-samba-[0-9]* pam-smbpass-[0-9]* winbind-[0-9]*
diff --git a/net/samba/distinfo b/net/samba/distinfo
index 49f333b5ad8..aec3e82078d 100644
--- a/net/samba/distinfo
+++ b/net/samba/distinfo
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.100 2014/06/24 14:06:30 taca Exp $
+$NetBSD: distinfo,v 1.100.6.1 2015/03/04 20:00:15 tron Exp $
-SHA1 (samba-3.6.24.tar.gz) = 6d48b55ab1e172b0c75035040f5aea65fbf0561e
-RMD160 (samba-3.6.24.tar.gz) = 0a57c49ee4a49408e75af02741f6c530828ea63f
-Size (samba-3.6.24.tar.gz) = 34122116 bytes
+SHA1 (samba-3.6.25.tar.gz) = 86fbfcfe80454cc7dbe510e7d58c02922cac3efa
+RMD160 (samba-3.6.25.tar.gz) = 4df673ddac2a3fc8590820c8651e10f0dac90281
+Size (samba-3.6.25.tar.gz) = 34121828 bytes
SHA1 (patch-aa) = 6c8497adce78e8b1dea2a0402d4a980b67b57b8e
SHA1 (patch-ab) = eb680f72ab0118e57d1b322aba869ac798b27e17
SHA1 (patch-ac) = 25edbd616199b7dcb41f87aa1374d0bdf19cafec