Update to version 4.0.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9094afb6f6 2026-04-25 01:21:36.172493+00:00 -------------------------------------------------------------------------------- Name : smb4k Product : Fedora 44 Version : 4.0.6 Release : 1.fc44 URL : https://smb4k.sourceforge.net/ Summary : The SMB/CIFS Share Browser for KDE Description : Smb4K is an SMB/CIFS share browser for KDE. It uses the Samba software suite to access the SMB/CIFS shares of the local network neighborhood. Its purpose is to provide a program that's easy to use and has as many features as possible. -------------------------------------------------------------------------------- Update Information: Update to version 4.0.6 -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 15 2026 Packit - 4.0.6-1 - Update to version 4.0.6 - Resolves: rhbz#2365800 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2365800 - smb4k-4.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2365800 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9094afb6f6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 4.0.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4ce552d940 2026-04-18 01:08:05.671412+00:00 -------------------------------------------------------------------------------- Name : smb4k Product : Fedora 42 Version : 4.0.6 Release : 1.fc42 URL : https://smb4k.sourceforge.net/ Summary : The SMB/CIFS Share Browser for KDE Description : Smb4K is an SMB/CIFS share browser for KDE. It uses the Samba software suite to access the SMB/CIFS shares of the local network neighborhood. Its purpose is to provide a program that's easy to use and has as many features as possible. -------------------------------------------------------------------------------- Update Information: Update to version 4.0.6 -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 15 2026 Packit - 4.0.6-1 - Update to version 4.0.6 - Resolves: rhbz#2365800 * Sat Jan 17 2026 Fedora Release Engineering - 4.0.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jul 25 2025 Fedora Release Engineering - 4.0.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2365800 - smb4k-4.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2365800 [ 2 ] Bug #2443263 - CVE-2025-66003 smb4k: smb4k local root exploit [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2443263 [ 3 ] Bug #2443267 - CVE-2025-66002 smb4k: SMB4K Arbitrary Mount [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2443267 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4ce552d940' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 2 vulnerabilities can now be installed.. # smb4k-4.0.5-1.2 on GA media Announcement ID: openSUSE-SU-2026:10370-1 Rating: moderate Cross-References: * CVE-2017-8849 * CVE-2025-66002 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the smb4k-4.0.5-1.2 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * smb4k 4.0.5-1.2 * smb4k-doc 4.0.5-1.2 * smb4k-lang 4.0.5-1.2 ## References: * https://www.suse.com/security/cve/CVE-2017-8849.html * https://www.suse.com/security/cve/CVE-2025-66002.html . Update for openSUSE Tumbleweed addresses moderate rating for smb4k, resolving two security issues effectively. . openSUSE update,smb4k security fix,moderate security issue. . LinuxSecurity.com Team
Two vulnerabilities were discovered in smb4k, a KDE desktop utility which allows unprivileged mounting of Samba/CIFS network shares, which may result in local denial of service or local privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 4.0.0-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6092-1
Sebastian Krahmer discovered that a programming error in the mount helper binary of the Smb4k Samba network share browser may result in local privilege escalation. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3951-1
Sebastian Krahmer from SUSE discovered that smb4k, a Samba (SMB) share advanced browser, contains a logic flaw in which the mount helper binary does not properly verify the mount command it is being asked to run. . Hash: SHA512 Package : smb4k Version : 1.2.1-2~deb7u1 CVE ID : CVE-2017-8849 Debian Bug : 862505 Sebastian Krahmer from SUSE discovered that smb4k, a Samba (SMB) share advanced browser, contains a logic flaw in which the mount helper binary does not properly verify the mount command it is being asked to run. This allows local users to call any other binary as root. The issue is resolved by backporting version 1.2.1-2 from Debian 9 "Stretch". For Debian 7 "Wheezy", these problems have been fixed in version 1.2.1-2~deb7u1. We recommend that you upgrade your smb4k packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Stay informed about the smb4k patch addressing a logic vulnerability that grants local root permissions. Enhance your security by upgrading.. Debian LTS,smb4k update,security risk,access control flaw,software update. . Severity: Important. LinuxSecurity.com Team
Update smb4k to 1.2.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-d51eedb333 2017-06-12 13:04:19.514282 --------------------------------------------------------------------------------Name : smb4k Product : Fedora 26 Version : 1.2.3 Release : 1.fc26 URL : https://sourceforge.net/p/smb4k/home/Home/ Summary : The SMB/CIFS Share Browser for KDE Description : Smb4K is an SMB/CIFS share browser for KDE. It uses the Samba software suite to access the SMB/CIFS shares of the local network neighborhood. Its purpose is to provide a program that's easy to use and has as many features as possible. --------------------------------------------------------------------------------Update Information: Update smb4k to 1.2.3 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade smb4k' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-8849. https://kde.org/info/security/advisory-20170510-2.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f7849e04f4 2017-06-09 18:48:36.528484 --------------------------------------------------------------------------------Name : smb4k Product : Fedora 26 Version : 1.2.2 Release : 3.fc26 URL : https://smb4k.sourceforge.io/ Summary : The SMB/CIFS Share Browser for KDE Description : Smb4K is an SMB/CIFS share browser for KDE. It uses the Samba software suite to access the SMB/CIFS shares of the local network neighborhood. Its purpose is to provide a program that's easy to use and has as many features as possible. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8849. https://kde.org/info/security/advisory-20170510-2.txt --------------------------------------------------------------------------------References: [ 1 ] Bug #1449658 - CVE-2017-8849 smb4k: unauthorized local command execution as root [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449658 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade smb4k' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.