Here are the details from the Slackware 15.0 ChangeLog: patches/packages/samba-4.15.13-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: This is the Samba CVE for the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability disclosed by Microsoft on Nov 8 2022. A Samba Active Directory DC will issue weak rc4-hmac session keys for use between modern clients and servers despite all modern Kerberos implementations supporting the aes256-cts-hmac-sha1-96 cipher. On Samba Active Directory DCs and members 'kerberos encryption types = legacy' would force rc4-hmac as a client even if the server supports aes128-cts-hmac-sha1-96 and/or aes256-cts-hmac-sha1-96. This is the Samba CVE for the Windows Kerberos Elevation of Privilege Vulnerability disclosed by Microsoft on Nov 8 2022. A service account with the special constrained delegation permission could forge a more powerful ticket than the one it was presented with. The "RC4" protection of
Read the Full AdvisoryThanks to the friendly folks at the OSU Open Source Lab
(https://osuosl.org/) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for
additional mirror sites near you.
Updated package for Slackware 15.0:
Updated package for Slackware x86_64 15.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:
Slackware 15.0 package:
4f00b47c418d2cc088c583214fcae013 samba-4.15.13-i586-1_slack15.0.txz
Slackware x86_64 15.0 package:
17a8269e24b94c18079ab854d99c4558 samba-4.15.13-x86_64-1_slack15.0.txz
Slackware -current package:
742f1ba1ddcb483294d8c8b172aaa8b4 n/samba-4.17.4-i586-1.txz
Slackware x86_64 -current package:
dfb34c60cfe6a4dea5d3ab03ddc109f7 n/samba-4.17.4-x86_64-1.txz
Get the latest Linux and open source security news straight to your inbox.
Installation instructions: Upgrade the package as root: # upgradepkg samba-4.15.13-i586-1_slack15.0.txz Then, if Samba is running restart it: # /etc/rc.d/rc.samba restart