Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security fix for CVE-2024-38439, CVE-2024-38440, and CVE-2024-38441. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-900475e0f7 2024-07-09 01:53:44.500984 -------------------------------------------------------------------------------- Name : netatalk Product : Fedora 40 Version : 3.2.1 Release : 1.fc40 URL : https://netatalk.io/ Summary : Open Source Apple Filing Protocol(AFP) File Server Description : Netatalk is a freely-available Open Source AFP file server. A *NIX/*BSD system running Netatalk is capable of serving many Macintosh clients simultaneously as an AppleShare file server (AFP). -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2024-38439, CVE-2024-38440, and CVE-2024-38441 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 30 2024 Andrew Bauer - 5:3.2.1-1 - 3.2.1 release, fixes CVE-2024-38439, CVE-2024-38440, and CVE-2024-38441 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2292817 - CVE-2024-38439 CVE-2024-38441 CVE-2024-38440 netatalk: multiple vulnerabilities https://bugzilla.redhat.com/show_bug.cgi?id=2292817 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-900475e0f7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
3.1.18 release Security fix for CVE-2022-22995. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-cec97f7b5d 2023-10-14 01:30:50.983256 -------------------------------------------------------------------------------- Name : netatalk Product : Fedora 38 Version : 3.1.18 Release : 1.fc38 URL : https://netatalk.io/ Summary : Open Source Apple Filing Protocol(AFP) File Server Description : Netatalk is a freely-available Open Source AFP file server. A *NIX/*BSD system running Netatalk is capable of serving many Macintosh clients simultaneously as an AppleShare file server (AFP). -------------------------------------------------------------------------------- Update Information: 3.1.18 release Security fix for CVE-2022-22995 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 5 2023 Andrew Bauer - 5:3.1.18-1 - 3.1.18 release - Fixes CVE-2022-22995 * Thu Sep 28 2023 Andrew Bauer - 5:3.1.17-2 - buildrequire mariadb-connector-c-devel for all but el7 - minor changes to other specfile conditionals -------------------------------------------------------------------------------- References: [ 1 ] Bug #2069298 - CVE-2022-22995 netatalk: default configuration allows the arbitrary writing of files https://bugzilla.redhat.com/show_bug.cgi?id=2069298 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-cec97f7b5d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
3.1.18 release Security fix for CVE-2022-22995. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ef901c862c 2023-10-14 01:26:08.208325 -------------------------------------------------------------------------------- Name : netatalk Product : Fedora 37 Version : 3.1.18 Release : 1.fc37 URL : https://netatalk.io/ Summary : Open Source Apple Filing Protocol(AFP) File Server Description : Netatalk is a freely-available Open Source AFP file server. A *NIX/*BSD system running Netatalk is capable of serving many Macintosh clients simultaneously as an AppleShare file server (AFP). -------------------------------------------------------------------------------- Update Information: 3.1.18 release Security fix for CVE-2022-22995 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 5 2023 Andrew Bauer - 5:3.1.18-1 - 3.1.18 release - Fixes CVE-2022-22995 * Thu Sep 28 2023 Andrew Bauer - 5:3.1.17-2 - buildrequire mariadb-connector-c-devel for all but el7 - minor changes to other specfile conditionals -------------------------------------------------------------------------------- References: [ 1 ] Bug #2069298 - CVE-2022-22995 netatalk: default configuration allows the arbitrary writing of files https://bugzilla.redhat.com/show_bug.cgi?id=2069298 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ef901c862c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to Samba 4.12.15 - Security fixes for CVE-2021-20254. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-7026246ea9 2021-05-08 01:10:02.820026 --------------------------------------------------------------------------------Name : samba Product : Fedora 32 Version : 4.12.15 Release : 0.fc32 URL : Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. --------------------------------------------------------------------------------Update Information: Update to Samba 4.12.15 - Security fixes for CVE-2021-20254 --------------------------------------------------------------------------------ChangeLog: * Thu Apr 29 2021 Guenther Deschner - 4.12.15-0 - Update to Samba 4.12.15 - resolves: #1949442, #1955027 - Security fixes for CVE-2021-20254 --------------------------------------------------------------------------------References: [ 1 ] Bug #1949442 - CVE-2021-20254 samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token https://bugzilla.redhat.com/show_bug.cgi?id=1949442 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-7026246ea9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Stefan Metzmacher discovered a flaw in Samba, a SMB/CIFS file, print, and login server for Unix. Specific combinations of parameters and permissions can allow user to escape from the share path definition and see the complete '/' filesystem. Unix permission checks in the kernel . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4513-1
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3740-1
Moderate: samba and samba3x security update. Date: Wed, 9 Jul 2014 18:43:07 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: samba and samba3x on SL5.x, SL6.x i386/srpm/x86_64 MIME-Version: 1.0 Synopsis: Moderate: samba and samba3x security update Advisory ID: SLSA-2014:0866-1 Issue Date: 2014-07-09 CVE Numbers: CVE-2014-0244 CVE-2014-3493 -- A denial of service flaw was found in the way the sys_recvfile() function of nmbd, the NetBIOS message block daemon, processed non-blocking sockets. An attacker could send a specially crafted packet that, when processed, would cause nmbd to enter an infinite loop and consume an excessive amount of CPU time. (CVE-2014-0244) It was discovered that smbd, the Samba file server daemon, did not properly handle certain files that were stored on the disk and used a valid Unicode character in the file name. An attacker able to send an authenticated non-Unicode request that attempted to read such a file could cause smbd to crash. (CVE-2014-3493) After installing this update, the smb service will be restarted automatically. -- SL5 x86_64 samba3x-3.6.6-0.140.el5_10.x86_64.rpm samba3x-domainjoin-gui-3.6.6-0.140.el5_10.x86_64.rpm samba3x-winbind-3.6.6-0.140.el5_10.i386.rpm samba3x-doc-3.6.6-0.140.el5_10.x86_64.rpm samba3x-client-3.6.6-0.140.el5_10.x86_64.rpm samba3x-winbind-devel-3.6.6-0.140.el5_10.i386.rpm samba3x-common-3.6.6-0.140.el5_10.x86_64.rpm samba3x-winbind-devel-3.6.6-0.140.el5_10.x86_64.rpm samba3x-winbind-3.6.6-0.140.el5_10.x86_64.rpm samba3x-swat-3.6.6-0.140.el5_10.x86_64.rpm samba3x-debuginfo-3.6.6-0.140.el5_10.i386.rpm samba3x-debuginfo-3.6.6-0.140.el5_10.x86_64.rpm i386 samba3x-winbind-3.6.6-0.140.el5_10.i386.rpm samba3x-domainjoin-gui-3.6.6-0.140.el5_10.i386.rpm samba3x-doc-3.6.6-0.140.el5_10.i386.rpm samba3x-winbind-devel-3.6.6-0.140.el5_10.i386.rpm samba3x-3.6.6-0.140.el5_10.i386.rpm samba3x-client-3.6.6-0.140.el5_10.i386.rpm samba3x-swat-3.6.6-0.140.el5_10.i386.rpm samba3x-common-3.6.6-0.140.el5_10.i386.rpm samba3x-debuginfo-3.6.6-0.140.el5_10.i386.rpm srpm samba3x-3.6.6-0.140.el5_10.src.rpm noarch samba3x-debuginfo-3.6.6-0.140.el5_10.x86_64.rpm samba3x-debuginfo-3.6.6-0.140.el5_10.i386.rpm SL6 x86_64 samba-common-3.6.9-169.el6_5.i686.rpm samba-winbind-clients-3.6.9-169.el6_5.x86_64.rpm libsmbclient-devel-3.6.9-169.el6_5.x86_64.rpm samba-doc-3.6.9-169.el6_5.x86_64.rpm samba-3.6.9-169.el6_5.x86_64.rpm libsmbclient-devel-3.6.9-169.el6_5.i686.rpm samba-winbind-3.6.9-169.el6_5.x86_64.rpm libsmbclient-3.6.9-169.el6_5.x86_64.rpm libsmbclient-3.6.9-169.el6_5.i686.rpm samba-domainjoin-gui-3.6.9-169.el6_5.x86_64.rpm samba-swat-3.6.9-169.el6_5.x86_64.rpm samba-client-3.6.9-169.el6_5.x86_64.rpm samba-winbind-krb5-locator-3.6.9-169.el6_5.x86_64.rpm samba-winbind-devel-3.6.9-169.el6_5.x86_64.rpm samba-winbind-clients-3.6.9-169.el6_5.i686.rpm samba-winbind-devel-3.6.9-169.el6_5.i686.rpm samba-common-3.6.9-169.el6_5.x86_64.rpm samba-debuginfo-3.6.9-169.el6_5.i686.rpm samba-debuginfo-3.6.9-169.el6_5.x86_64.rpm srpm samba-3.6.9-169.el6_5.src.rpm i386 samba-common-3.6.9-169.el6_5.i686.rpm samba-3.6.9-169.el6_5.i686.rpm libsmbclient-devel-3.6.9-169.el6_5.i686.rpm samba-doc-3.6.9-169.el6_5.i686.rpm samba-swat-3.6.9-169.el6_5.i686.rpm libsmbclient-3.6.9-169.el6_5.i686.rpm samba-winbind-3.6.9-169.el6_5.i686.rpm samba-winbind-krb5-locator-3.6.9-169.el6_5.i686.rpm samba-winbind-clients-3.6.9-169.el6_5.i686.rpm samba-winbind-devel-3.6.9-169.el6_5.i686.rpm samba-client-3.6.9-169.el6_5.i686.rpm samba-domainjoin-gui-3.6.9-169.el6_5.i686.rpm samba-debuginfo-3.6.9-169.el6_5.i686.rpm noarch samba-debuginfo-3.6.9-169.el6_5.x86_64.rpm samba-debuginfo-3.6.9-169.el6_5.i686.rpm - Scientific Linux Development Team . Stay informed about the recent samba and samba3x security patch that tackles denial of service vulnerabilities and crash problems in Scientific Linux.. samba security advisory, Scientific Linux update,samba3x patch. . Severity: Important. LinuxSecurity.com Team
A vulnerability has been discovered in samba, a commonly used LanManager-like file and printer server for Unix. A remote attacker may be able to gain access to files which exist outside of the share's defined path.. -------------------------------------------------------------------------- Debian Security Advisory DSA 600-1
Get the latest Linux and open source security news straight to your inbox.