summaryrefslogtreecommitdiff
path: root/net/samba
AgeCommit message (Collapse)AuthorFilesLines
2017-06-01Use public SHLIB_TYPE instead of private _OPSYS_SHLIB_TYPE.jlam1-2/+2
2017-05-24Adapt & apply fix forhe3-3/+26
https://bugzilla.samba.org/show_bug.cgi?id=12780 (non-public) from https://www.samba.org/samba/ftp/patches/security/samba-4.6.3-4.5.9-4.4.13-CVE-2017-7494.patch Should fix CVE-2017-7494. Bump PKGREVISION.
2017-05-19Bump PKGREVISION for cups15 -> cups change.prlw11-2/+2
2017-05-19Switch all cups15 packages to use cups.prlw11-2/+2
2016-09-01 - Drop MASTER_SITE pingable, but no reponse with ftpmef1-2/+1
2016-09-01 - Drop unpingable MASTER_SITEmef1-3/+1
2016-07-09Bump PKGREVISION for perl-5.24.0 for everything mentioning perl.wiz1-2/+2
2016-06-08Remove the stability entity, it has no meaning outside of an official context.jperkin1-1/+0
2016-06-08Change the service_bundle name to "export" to reduce diffs between thejperkin1-1/+1
original manifest.xml file and the output from "svccfg export".
2016-06-08Add or fix manpath entries to use the correct path.jperkin1-2/+2
2016-03-18Don't create the /usr/lib symlinks on SmartOS, it is a read-only mount.jperkin1-1/+3
2016-03-05Bump PKGREVISION for security/openssl ABI bump.jperkin1-2/+2
2016-02-29Various build and install fixes for Darwin.jperkin4-28/+55
2016-02-25Use OPSYSVARS.jperkin1-7/+3
2015-11-04Add SHA512 digests for distfiles for net categoryagc1-1/+2
Problems found with existing digests: Package haproxy distfile haproxy-1.5.14.tar.gz 159f5beb8fdc6b8059ae51b53dc935d91c0fb51f [recorded] da39a3ee5e6b4b0d3255bfef95601890afd80709 [calculated] Problems found locating distfiles: Package bsddip: missing distfile bsddip-1.02.tar.Z Package citrix_ica: missing distfile citrix_ica-10.6.115659/en.linuxx86.tar.gz Package djbdns: missing distfile djbdns-1.05-test25.diff.bz2 Package djbdns: missing distfile djbdns-cachestats.patch Package djbdns: missing distfile 0002-dnscache-cache-soa-records.patch Package gated: missing distfile gated-3-5-11.tar.gz Package owncloudclient: missing distfile owncloudclient-2.0.2.tar.xz Package poink: missing distfile poink-1.6.tar.gz Package ra-rtsp-proxy: missing distfile rtspd-src-1.0.0.0.tar.gz Package ucspi-ssl: missing distfile ucspi-ssl-0.70-ucspitls-0.1.patch Package waste: missing distfile waste-source.tar.gz Otherwise, existing SHA1 digests verified and found to be the same on the machine holding the existing distfiles (morden). All existing SHA1 digests retained for now as an audit trail.
2015-10-23Skip shlibs checks for samba loadable plugins on Darwin.tnn1-1/+2
All dylibs get their -install_name set to ${PREFIX}/lib/libname.lib, but plugins go in different directories which causes the check to misfire.
2015-06-12Recursive PKGREVISION bump for all packages mentioning 'perl',wiz1-2/+2
having a PKGNAME of p5-*, or depending such a package, for perl-5.22.0.
2015-05-29Fix Samba ability to use LDAP/SSL with a SHA2 certificatemanu3-2/+32
NetBSD's libc and Samba both proide SHA2 function with the same protoype, but with different private context structures. The Samba version must not override the libc version, otherwise they are used when using LDAP/SSL, through libldap/libssl/libcrypto but libcrtypo expect to use the libc flavor. Without this fix, Samba cannot connect to a LDAP directory that has a SHA2-signed certificate. This rather cryptic error is raised in smbd logs: error:0D0C5006:asn1 encoding routines:ASN1_item_verify:EVP lib
2015-05-19Restrict buildlink3 requirement, samba<4.ryoon1-3/+3
2015-05-10Fix pasto.ryoon1-2/+2
fam for File Alteration Monitor.
2015-03-01Account for the libraries installed on FreeBSDsevan1-0/+3
Reviewed by wiz@
2015-02-24Update samba package to 3.6.25.taca2-6/+6
============================== Release Notes for Samba 3.6.25 February 23, 2015 ============================== This is a security release in order to address CVE-2015-0240 (Unexpected code execution in smbd). o CVE-2015-0240: All versions of Samba from 3.5.0 to 4.2.0rc4 are vulnerable to an unexpected code execution vulnerability in the smbd file server daemon. A malicious client could send packets that may set up the stack in such a way that the freeing of memory in a subsequent anonymous netlogon packet could allow execution of arbitrary code. This code would execute with root privileges. o CVE-2014-0178: In preparing a response to an authenticated FSCTL_GET_SHADOW_COPY_DATA or FSCTL_SRV_ENUMERATE_SNAPSHOTS client request, affected versions of Samba do not initialize 8 bytes of the 16 byte SRV_SNAPSHOT_ARRAY response field. The uninitialized buffer is sent back to the client. A non-default VFS module providing the get_shadow_copy_data_fn() hook must be explicitly enabled for Samba to process the aforementioned client requests. Therefore, only configurations with "shadow_copy" or "shadow_copy2" specified for the "vfs objects" parameter are vulnerable.
2015-02-02SunOS inotify requires sys/filio.h for FIONREAD.jperkin2-1/+18
2015-01-23tell pidfile nameobache3-3/+6
2015-01-20Do not enable ads on Darwin-10+ by default.wiz1-2/+6
Fixes PR 49590 by Youri Mouton.
2014-07-21Haiku also supports some vfs modules too.obache1-0/+3
from diger.
2014-07-21Move Darwin specific PLIST entries to PLIST.Darwin, same as SunOS, Linux.obache3-11/+6
2014-06-24Update samba to 3.6.24, security release.taca2-7/+6
============================== Release Notes for Samba 3.6.24 June 23, 2014 ============================== This is a security release in order to address CVE-2014-0244 (Denial of service - CPU loop) and CVE-2014-3493 (Denial of service - Server crash/memory corruption). o CVE-2014-0244: All current released versions of Samba are vulnerable to a denial of service on the nmbd NetBIOS name services daemon. A malformed packet can cause the nmbd server to loop the CPU and prevent any further NetBIOS name service. This flaw is not exploitable beyond causing the code to loop expending CPU resources. o CVE-2014-3493: All current released versions of Samba are affected by a denial of service crash involving overwriting memory on an authenticated connection to the smbd file server.
2014-06-18Bump PKGREVISION for cups -> cups15 change.wiz1-2/+2
2014-06-18Switch all cups packages to use cups15.wiz1-2/+2
2014-06-10security/PAM/module.mk is gone.joerg1-3/+4
2014-05-29Bump for perl-5.20.0.wiz1-2/+2
Do it for all packages that * mention perl, or * have a directory name starting with p5-*, or * depend on a package starting with p5- like last time, for 5.18, where this didn't lead to complaints. Let me know if you have any this time.
2014-05-14Add SMF manifestwiedi2-1/+47
2014-03-18Remove "us5.samba.org" URL which no longer works.tron1-2/+1
2014-03-18Add patch to build problem with newer readline.taca2-1/+17
2014-03-17Update samba to 3.6.23.taca2-7/+6
============================== Release Notes for Samba 3.6.23 March 11, 2014 ============================== This is a security release in order to address CVE-2013-4496 (Password lockout not enforced for SAMR password changes). o CVE-2013-4496: Samba versions 3.4.0 and above allow the administrator to implement locking out Samba accounts after a number of bad password attempts. However, all released versions of Samba did not implement this check for password changes, such as are available over multiple SAMR and RAP interfaces, allowing password guessing attacks.
2014-03-13Set USE_GCC_RUNTIME=yes for packages which build shared libraries but dojperkin1-1/+3
not use libtool to do so. This is required to correctly depend upon a gcc runtime package (e.g. gcc47-libs) when using USE_PKGSRC_GCC_RUNTIME.
2014-03-11Remove example rc.d scripts from PLISTs.jperkin1-5/+1
These are now handled dynamically if INIT_SYSTEM is set to "rc.d", or ignored otherwise.
2014-03-03Replace log dir in the default sample config file correctly.obache3-6/+12
Bump PKGREVISION.
2014-03-03simplify with SUBST_VARS.obache1-7/+2
2014-02-27Remove pam_smbpass README, build machine environment issue, apologies.jperkin1-2/+1
2014-02-26Add missing README for the pam case.jperkin1-1/+2
2014-02-12Recursive PKGREVISION bump for OpenSSL API version bump.tron1-1/+2
2014-01-28Use GNU_CONFIGURE_LIBDIR for --libdir.obache1-2/+2
2013-12-09Update samba to 3.6.22; Security fix for CVE-2012-6150.taca2-6/+6
Changes since 3.6.21: --------------------- o Jeremy Allison <jra@samba.org> * BUG 10185: CVE-2013-4408: Correctly check DCE-RPC fragment length field. o Stefan Metzmacher <metze@samba.org> * BUG 10185: CVE-2013-4408: Correctly check DCE-RPC fragment length field. o Noel Power <noel.power@suse.com> * BUGs 10300, 10306: CVE-2012-6150: Fail authentication if user isn't member of *any* require_membership_of specified groups. Changes since 3.6.20: --------------------- o Jeremy Allison <jra@samba.org> * BUG 10139: Valid utf8 filenames cause "invalid conversion error" messages. * BUG 10167: s3-smb2 server: smb2 breaks "smb encryption = mandatory". * BUG 10187: Missing talloc_free can leak stackframe in error path. * BUG 10247: xattr: Fix listing EAs on *BSD for non-root users. o Korobkin <korobkin+samba@gmail.com> * BUG 10118: Raise debug level for being unable to open a printer. o Volker Lendecke <vl@samba.org> * BUG 10195: nsswitch: Fix short writes in winbind_write_sock. o Arvid Requate <requate@univention.de> * BUG 10267: Fix Windows 8 printing via local printer drivers. o Andreas Schneider <asn@cryptomilk.org> * BUG 10194: Make offline logon cache updating for cross child domain group membership.
2013-11-12Changes 3.6.20:adam2-6/+6
These are security releases in order to address CVE-2013-4475 (ACLs are not checked on opening an alternate data stream on a file or directory) and CVE-2013-4476 (Private key in key.pem world readable).
2013-10-09Update samba to 3.6.19.taca2-6/+6
Changes since 3.6.18: --------------------- o Jeremy Allison <jra@samba.org> * BUG 5917: Make Samba work on site with Read Only Domain Controller. o Christian Ambach <ambi@samba.org> * BUG 8955: NetrServerPasswordSet2 timeout is too short. o Günther Deschner <gd@samba.org> * BUG 9899: Fix fallback to ncacn_np in cm_connect_lsat(). * BUG 9615: Fix fallback to ncacn_np in cm_connect_lsat(). * BUG 10127: Fix 'smbstatus' as non-root user. o Volker Lendecke <vl@samba.org> * BUG 8955: Give machine password changes 10 minutes of time. * BUG 10106: Honour output buffer length set by the client for SMB2 GetInfo requests. * BUG 10114: Handle Dropbox (write-only-directory) case correctly in pathname lookup. o Karolin Seeger <kseeger@samba.org> * BUG 10076: Fix variable list in man vfs_crossrename. o Andreas Schneider <asn@samba.org> * BUG 9994: s3-winbind: Do not delete an existing valid credential cache. * BUG 10073: 'net ads join': Fix segmentation fault in create_local_private_krb5_conf_for_domain. o Richard Sharpe <realrichardsharpe@gmail.com> * BUG 10097: MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba.
2013-08-14Changes 3.6.18:adam2-6/+6
* BUG 9777: vfs_dirsort uses non-stackable calls, dirfd(), malloc instead of talloc and doesn't cope with directories being modified whilst reading. * BUG 9678: Windows 8 Roaming profiles fail. * BUG 9636: Fix parsing linemarkers in preprocessor output. * BUG 9880: Use of wrong RFC2307 primary group field. * BUG 9983: Fix output of syslog-facility check. * BUG 10064: Linux kernel oplock breaks can miss signals.
2013-08-12Update samba to 3.6.17, security release.taca18-78/+78
============================== Release Notes for Samba 3.6.17 August 05, 2013 ============================== This is a security release in order to address CVE-2013-4124 (Missing integer wrap protection in EA list reading can cause server to loop with DOS). o CVE-2013-4124: All current released versions of Samba are vulnerable to a denial of service on an authenticated or guest connection. A malformed packet can cause the smbd server to loop the CPU performing memory allocations and preventing any further service. A connection to a file share, or a local account is needed to exploit this problem, either authenticated or unauthenticated if guest connections are allowed. This flaw is not exploitable beyond causing the code to loop allocating memory, which may cause the machine to exceed memory limits. Changes since 3.6.16: --------------------- o Jeremy Allison <jra@samba.org> * BUG 10010: CVE-2013-4124: Missing integer wrap protection in EA list reading can cause server to loop with DOS.
2013-07-15* .include "../../devel/readline/buildlink3.mk" with USE_GNU_READLINE=yesryoon1-2/+1
are replaced with .include "../../devel/readline/buildlink3.mk", and USE_GNU_READLINE are removed, * .include "../../devel/readline/buildlink3.mk" without USE_GNU_READLINE are replaced with .include "../../mk/readline.buildlink3.mk".