diff options
author | taca <taca@pkgsrc.org> | 2011-07-27 00:53:37 +0000 |
---|---|---|
committer | taca <taca@pkgsrc.org> | 2011-07-27 00:53:37 +0000 |
commit | d5937f4400d6de603a3d3c0f43fefd640debac80 (patch) | |
tree | 8df1eb3ae1a846cc02fd5482f42e5025c57b300d /security/opendnssec | |
parent | 74098265aba9cb1ea5cb914f5b67867ce968bde8 (diff) | |
download | pkgsrc-d5937f4400d6de603a3d3c0f43fefd640debac80.tar.gz |
Update samba33 package to 3.3.16; security fix for swat.
==============================
Release Notes for Samba 3.3.16
July 26, 2011
==============================
This is a security release in order to address
CVE-2011-2522 (Cross-Site Request Forgery in SWAT) and
CVE-2011-2694 (Cross-Site Scripting vulnerability in SWAT).
o CVE-2011-2522:
The Samba Web Administration Tool (SWAT) in Samba versions
3.0.x to 3.5.9 are affected by a cross-site request forgery.
o CVE-2011-2694:
The Samba Web Administration Tool (SWAT) in Samba versions
3.0.x to 3.5.9 are affected by a cross-site scripting
vulnerability.
Please note that SWAT must be enabled in order for these
vulnerabilities to be exploitable. By default, SWAT
is *not* enabled on a Samba install.
Changes since 3.3.15
--------------------
o Kai Blin <kai@samba.org>
* BUG 8289: SWAT contains a cross-site scripting vulnerability.
* BUG 8290: CSRF vulnerability in SWAT.
Diffstat (limited to 'security/opendnssec')
0 files changed, 0 insertions, 0 deletions