NEWS[4.18.3]: Samba 4.18.3 Available for Download
[samba-web.git] / history / samba-4.9.6.html
1 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
2  "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
3 <html xmlns="http://www.w3.org/1999/xhtml">
4 <head>
5 <title>Samba 4.9.6 - Release Notes</title>
6 </head>
7 <body>
8 <H2>Samba 4.9.6 Available for Download</H2>
9 <p>
10 <a href="https://download.samba.org/pub/samba/stable/samba-4.9.6.tar.gz">Samba 4.9.6 (gzipped)</a><br>
11 <a href="https://download.samba.org/pub/samba/stable/samba-4.9.6.tar.asc">Signature</a>
12 </p>
13 <p>
14 <a href="https://download.samba.org/pub/samba/patches/samba-4.9.5-4.9.6.diffs.gz">Patch (gzipped) against Samba 4.9.5</a><br>
15 <a href="https://download.samba.org/pub/samba/patches/samba-4.9.5-4.9.6.diffs.asc">Signature</a>
16 </p>
17 <p>
18 <pre>
19                    =============================
20                    Release Notes for Samba 4.9.6
21                            April 8, 2019
22                    =============================
23
24
25 This is a security release in order to address the following defects:
26
27 o  CVE-2019-3870 (World writable files in Samba AD DC private/ dir)
28 o  CVE-2019-3880 (Save registry file outside share as unprivileged user)
29
30
31 =======
32 Details
33 =======
34
35 o  CVE-2019-3870:
36    During the provision of a new Active Directory DC, some files in the private/
37    directory are created world-writable.
38
39 o  CVE-2019-3880:
40    Authenticated users with write permission can trigger a symlink traversal to
41    write or detect files outside the Samba share.
42
43 For more details and workarounds, please refer to the security advisories.
44
45
46 Changes since 4.9.5:
47 --------------------
48
49 o  Andrew Bartlett &lt;abartlet@samba.org&gt;
50    * BUG 13834: CVE-2019-3870: pysmbd: Ensure a zero umask is set for
51      smbd.mkdir().
52
53 o  Jeremy Allison &lt;jra@samba.org&gt;
54    * BUG 13851: CVE-2018-14629: rpc: winreg: Remove implementations of
55      SaveKey/RestoreKey.
56
57
58 </pre>
59 </p>
60 </body>
61 </html>