NEWS[4.18.1]: Samba 4.18.5, 4.17.10 and 4.16.11 Security Releases are available for...
[samba-web.git] / history / security.html
1 <!--#include virtual="/samba/header.html" --> 
2   <title>Samba - Security Updates and Information</title>
3 <!--#include virtual="header_history.html" -->
4
5 <h2>Samba Security Releases</h2>
6
7     <p>Security releases for Samba are listed below by their release
8 date. The previously affected versions of Samba are listed alongside
9 the appropriate security concern. For complete information, follow the
10 link to full release notes for each release.</p>
11
12    <p>Samba's <a href="https://wiki.samba.org/index.php/Samba_Security_Process">
13       coordinated security release and disclosure process</a> is followed
14       and new versions of Samba are released for
15       <a href="https://wiki.samba.org/index.php/Samba_Release_Planning">
16       supported Samba versions</a>.</p>
17
18         <tr>
19         <td>19 July 2023</td>
20         <td>
21         <a href="/samba/ftp/patches/security/samba-4.18.5-security-2023-07-19.patch">
22         patch for Samba 4.18.5</a><br/>
23         <a href="/samba/ftp/patches/security/samba-4.17.10-security-2023-07-19.patch">
24         patch for Samba 4.17.10</a><br/>
25         <a href="/samba/ftp/patches/security/samba-4.16.11-security-2023-07-19.patch">
26         patch for Samba 4.16.11</a><br/>
27         </td>
28         <td>
29         CVE-2022-2127, CVE-2023-3347, CVE-2023-34966, CVE-2023-34967 and CVE-2023-34968.
30         Please see announcements for details.
31         </td>
32         <td>All versions of Samba since 4.0 prior to 4.16.11, 4.17.10, 4.18.5.</td>
33         <td>
34 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2127">CVE-2022-2127</a>,
35 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3347">CVE-2023-3347</a>,
36 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34966">CVE-2023-34966</a>,
37 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34967">CVE-2023-34967</a>,
38 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34968">CVE-2023-34968</a>.
39         </td>
40         <td>
41 <a href="/samba/security/CVE-2022-2031.html">Announcement</a>,
42 <a href="/samba/security/CVE-2023-3347.html">Announcement</a>,
43 <a href="/samba/security/CVE-2023-34966.html">Announcement</a>,
44 <a href="/samba/security/CVE-2023-34967.html">Announcement</a>,
45 <a href="/samba/security/CVE-2023-34968.html">Announcement</a>.
46         </td>
47         </tr>
48
49    <p>A list of public <a href="https://bugzilla.samba.org/buglist.cgi?f1=alias&o1=regexp&order=Last Changed&product=PIDL&product=Samba 2.2&product=Samba 3.0&product=Samba 3.2&product=Samba 3.3&product=Samba 3.4&product=Samba 3.5&product=Samba 3.6&product=Samba 4.0&product=Samba 4.1 and newer&query_format=advanced&v1=^CVE-.*">
50       Samba Security Bugs</a> is available.  Some minor issues will
51       only be listed in <a href="https://bugzilla.samba.org">
52       The Samba Bugzilla</a> and not here, if they did not result
53       in a security release</p>
54
55     <table class="security_table">
56       <th colspan="6">Samba Security Releases</th>
57       <tr >
58         <td><em>Date Issued</em></td>
59         <td><em>Download</em></td>
60         <td><em>Known Issue(s)</em></td>
61         <td><em>Affected Releases</em></td>
62         <td><em>CVE ID #</em></td>
63         <td><em>Details</em></td>
64       </tr>
65
66         <tr>
67         <td>29 March 2023</td>
68         <td>
69         <a href="/samba/ftp/patches/security/samba-4.18.1-security-2023-03-29.patch">
70         patch for Samba 4.18.1</a><br/>
71         <a href="/samba/ftp/patches/security/samba-4.17.7-security-2023-03-29.patch">
72         patch for Samba 4.17.7</a><br/>
73         <a href="/samba/ftp/patches/security/samba-4.16.10-security-2023-03-29.patch">
74         patch for Samba 4.16.10</a><br/>
75         </td>
76         <td>
77         CVE-2023-0225, CVE-2023-0922 and CVE-2023-0614.
78         Please see announcements for details.
79         </td>
80         <td>All versions of Samba since 4.0 prior to 4.16.10, 4.17.7, 4.18.1.</td>
81         <td>
82 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0225">CVE-2023-0225</a>,
83 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0922">CVE-2023-0922</a>,
84 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0614">CVE-2023-0614</a>.
85         </td>
86         <td>
87 <a href="/samba/security/CVE-2023-0225.html">Announcement</a>,
88 <a href="/samba/security/CVE-2023-0922.html">Announcement</a>,
89 <a href="/samba/security/CVE-2023-0614.html">Announcement</a>.
90         </td>
91         </tr>
92
93         <tr>
94         <td>15 December 2022</td>
95         <td>
96         Please see bug reports in <a href="https://bugzilla.samba.org">the Samba Bugzilla</a>.
97         </td>
98         <td>CVE-2022-37966, CVE-2022-37967, CVE-2022-38023 and CVE-2022-45141.
99         Please see announcements for details.
100         </td>
101         <td>All versions of Samba prior to 4.15.13, 4.16.8, 4.17.4.</td>
102         <td>
103 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38023">CVE-2022-38023</a>,
104 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37966">CVE-2022-37966</a>,
105 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37967">CVE-2022-37967</a>,
106 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45141">CVE-2022-45141</a>.
107         </td>
108         <td>
109 <a href="/samba/security/CVE-2022-38023.html">Announcement</a>,
110 <a href="/samba/security/CVE-2022-37966.html">Announcement</a>,
111 <a href="/samba/security/CVE-2022-37967.html">Announcement</a>,
112 <a href="/samba/security/CVE-2022-45141.html">Announcement</a>.
113         </td>
114     </tr>
115
116         <tr>
117         <td>15 November 2022</td>
118         <td><a href="/samba/ftp/patches/security/samba-4.17.3-security-2022-11-15.patch">
119         patch for Samba 4.17.3</a><br />
120         <a href="/samba/ftp/patches/security/samba-4.16.7-security-2022-11-15.patch">
121         patch for Samba 4.16.7</a><br />
122         <a href="/samba/ftp/patches/security/samba-4.15.12-security-2022-11-15.patch">
123         patch for Samba 4.15.12</a><br />
124         </td>
125         <td>Samba's Kerberos libraries and AD DC failed to guard against integer
126         overflows when parsing a PAC on a 32-bit system, which allowed an attacker
127         with a forged PAC to corrupt the heap.
128         </td>
129         <td>All versions of Samba prior to 4.15.12, 4.16.7, 4.17.3.</td>
130         <td>
131 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42898">CVE-2022-42898</a>.
132         </td>
133         <td>
134 <a href="/samba/security/CVE-2022-42898.html">Announcement</a>.
135         </td>
136     </tr>
137
138
139     <tr>
140         <td>25 October 2022</td>
141         <td><a href="/samba/ftp/patches/security/samba-4.17.2-security-2022-10-25.patch">
142         patch for Samba 4.17.2</a><br />
143         <a href="/samba/ftp/patches/security/samba-4.16.6-security-2022-10-25.patch">
144         patch for Samba 4.16.6</a><br />
145         <a href="/samba/ftp/patches/security/samba-4.15.11-security-2022-10-25.patch">
146         patch for Samba 4.15.11</a><br />
147         </td>
148         <td>CVE-2022-3437 and CVE-2022-3592.
149         Please see announcements for details.
150         </td>
151         <td>Please refer to the advisories.</td>
152         <td>
153 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3437">CVE-2022-3437</a>, 
154 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3592">CVE-2022-3592</a>.
155         </td>
156         <td>
157 <a href="/samba/security/CVE-2022-3437.html">Announcement</a>, 
158 <a href="/samba/security/CVE-2022-3592.html">Announcement</a>.
159         </td>
160         </tr>
161
162         <td>27 July 2022</td>
163         <td><a href="/samba/ftp/patches/security/samba-4.16.4-security-2022-07-27.patch">
164         patch for Samba 4.16.4</a><br />
165         <a href="/samba/ftp/patches/security/samba-4.15.9-security-2022-07-27.patch">
166         patch for Samba 4.15.9</a><br />
167         <a href="/samba/ftp/patches/security/samba-4.14.14-security-2022-07-27.patch">
168         patch for Samba 4.14.14</a><br />
169         </td>
170         <td>CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745 and CVE-2022-32746.
171         Please see announcements for details.
172         </td>
173         <td>Please refer to the advisories.</td>
174         <td>
175 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2031">CVE-2022-2031</a>, 
176 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32742">CVE-2022-32742</a>, 
177 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32744">CVE-2022-32744</a>, 
178 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32745">CVE-2022-32745</a>, 
179 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32746">CVE-2022-32746</a>.
180         </td>
181         <td>
182 <a href="/samba/security/CVE-2022-2031.html">Announcement</a>, 
183 <a href="/samba/security/CVE-2022-32742.html">Announcement</a>, 
184 <a href="/samba/security/CVE-2022-32744.html">Announcement</a>, 
185 <a href="/samba/security/CVE-2022-32745.html">Announcement</a>, 
186 <a href="/samba/security/CVE-2022-32746.html">Announcement</a>.
187         </td>
188         </tr>
189
190     <tr>
191         <td>31 January 2022</td>
192         <td><a href="/samba/ftp/patches/security/samba-4.15.5-security-2022-01-31.patch">
193         patch for Samba 4.15.5</a><br />
194         <a href="/samba/ftp/patches/security/samba-4.14.12-security-2022-01-31.patch">
195         patch for Samba 4.14.12</a><br />
196         <a href="/samba/ftp/patches/security/samba-4.13.17-security-2022-01-31.patch">
197         patch for Samba 4.13.17</a><br />
198         </td>
199         <td>CVE-2021-44141, CVE-2021-44142 and CVE-2022-0336. Please see announcements for details.
200         </td>
201         <td>Please refer to the advisories.</td>
202         <td>
203 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44141">CVE-2021-44141</a>, 
204 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44142">CVE-2021-44142</a>, 
205 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0336">CVE-2022-0336</a>.
206         </td>
207         <td>
208 <a href="/samba/security/CVE-2021-44141.html">Announcement</a>, 
209 <a href="/samba/security/CVE-2021-44142.html">Announcement</a>, 
210 <a href="/samba/security/CVE-2022-0336.html">Announcement</a>.
211         </td>
212         </tr>
213
214         <tr>
215         <td>10 January 2022</td>
216         <td><a href="/samba/ftp/patches/security/samba-4.13.16-security-2022-01-10.patch">
217         patch for Samba 4.13.16</a><br />
218         </td>
219         <td>Symlink race error can allow directory creation outside of the exported share.
220         </td>
221         <td>All versions of the Samba file server prior to 4.13.16</td>
222         <td>
223         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43566">CVE-2021-43566</a>.
224         </td>
225         <td>
226         <a href="/samba/security/CVE-2021-43566.html">Announcement</a>.
227         </td>
228         </tr>
229
230     <tr>
231         <td>9 November 2021</td>
232         <td><a href="/samba/ftp/patches/security/samba-4.15.1-security-2021-11-09.patch">
233         patch for Samba 4.15.1</a><br />
234         <a href="/samba/ftp/patches/security/samba-4.14.9-security-2021-11-09.patch">
235         patch for Samba 4.14.9</a><br />
236         <a href="/samba/ftp/patches/security/samba-4.13.13-security-2021-11-09.patch">
237         patch for Samba 4.13.13</a><br />
238         </td>
239         <td>CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719,
240 CVE-2020-25721, CVE-2020-25722, CVE-2021-3738 and CVE-2021-23192. Please see announcements for details.
241         </td>
242         <td>Please refer to the advisories.</td>
243         <td>
244 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2124">CVE-2016-2124</a>, 
245 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25717">CVE-2020-25717</a>, 
246 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25718">CVE-2020-25718</a>, 
247 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25719">CVE-2020-25719</a>, 
248 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25721">CVE-2020-25721</a>, 
249 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25722">CVE-2020-25722</a>, 
250 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3738">CVE-2021-3738</a>, 
251 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23192">CVE-2021-23192</a>.
252         </td>
253         <td>
254 <a href="/samba/security/CVE-2016-2124.html">Announcement</a>, 
255 <a href="/samba/security/CVE-2020-25717.html">Announcement</a>, 
256 <a href="/samba/security/CVE-2020-25718.html">Announcement</a>, 
257 <a href="/samba/security/CVE-2020-25719.html">Announcement</a>, 
258 <a href="/samba/security/CVE-2020-25721.html">Announcement</a>, 
259 <a href="/samba/security/CVE-2020-25722.html">Announcement</a>, 
260 <a href="/samba/security/CVE-2021-3738.html">Announcement</a>, 
261 <a href="/samba/security/CVE-2021-23192.html">Announcement</a>.
262         </td>
263     </tr>
264     <tr>
265         <td>29 Apr 2021</td>
266         <td><a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
267         patch for Samba 4.14.3</a><br />
268         <a href="/samba/ftp/patches/security/samba-4.13.7-security-2021-04-29.patch">
269         patch for Samba 4.13.7</a><br />
270         <a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
271         patch for Samba 4.12.14</a><br />
272         </td>
273         <td>Negative idmap cache entries can cause incorrect group entries in
274             the Samba file server process token.
275         </td>
276         <td>All versions since 3.6.0.</td>
277         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20254">CVE-2021-20254</a>
278         </td>
279         <td><a href="/samba/security/CVE-2021-20254.html">Announcement</a>
280         </td>
281     </tr>
282
283     <tr>
284         <td>24 Mar 2021</td>
285         <td><a href="/samba/ftp/patches/security/samba-4.14.0-security-2021-03-24.patch">
286         patch for Samba 4.14.0</a><br />
287         <a href="/samba/ftp/patches/security/samba-4.13.5-security-2021-03-24.patch">
288         patch for Samba 4.13.5</a><br />
289         <a href="/samba/ftp/patches/security/samba-4.12.12-security-2021-03-24.patch">
290         patch for Samba 4.12.12</a><br />
291         </td>
292         <td>CVE-2020-27840 and CVE-2021-20277. Please see announcements for details.
293         </td>
294         <td>Please refer to the advisories.</td>
295         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27840">CVE-2020-27840</a>,
296         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20277">CVE-2021-20277</a>.
297         </td>
298         <td><a href="/samba/security/CVE-2020-27840.html">Announcement</a>,
299         <a href="/samba/security/CVE-2021-20277.html">Announcement</a>.
300         </td>
301     </tr>
302
303     <tr>
304         <td>29 Oct 2020</td>
305         <td><a href="/samba/ftp/patches/security/samba-4.13.0-security-2020-10-29.patch">
306         patch for Samba 4.13.0</a><br />
307         <a href="/samba/ftp/patches/security/samba-4.12.8-security-2020-10-29.patch">
308         patch for Samba 4.12.8</a><br />
309         <a href="/samba/ftp/patches/security/samba-4.11.14-security-2020-10-29.patch">
310         patch for Samba 4.11.14</a><br />
311         </td>
312         <td>CVE-2020-14318, CVE-2020-14323 and CVE-2020-14383. Please see announcements for details.
313         </td>
314         <td>Please refer to the advisories.</td>
315         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14318">CVE-2020-14318</a>,
316         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14323">CVE-2020-14323</a>
317         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14383">CVE-2020-14383</a>.
318         </td>
319         <td><a href="/samba/security/CVE-2020-14318.html">Announcement</a>,
320         <a href="/samba/security/CVE-2020-14323.html">Announcement</a>,
321         <a href="/samba/security/CVE-2020-14383.html">Announcement</a>.
322         </td>
323     </tr>
324
325     <tr>
326         <td>18 Sep 2020</td>
327         <td><a href="/samba/ftp/patches/security/samba-4.12.6-security-2020-09-18.patch">
328         patch for Samba 4.12.6</a><br />
329         <a href="/samba/ftp/patches/security/samba-4.11.12-security-2020-09-18.patch">
330         patch for Samba 4.11.12</a><br />
331         <a href="/samba/ftp/patches/security/samba-4.10.17-security-2020-09-18.patch">
332         patch for Samba 4.10.17</a><br />
333         </td>
334         <td>CVE-2020-1472.
335             Please see announcements for details.
336         </td>
337         <td>Please refer to the advisory.</td>
338         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1472">CVE-2020-1472</a>.
339         </td>
340         <td><a href="/samba/security/CVE-2020-1472.html">Announcement</a>,
341         </td>
342     </tr>
343
344     <tr>
345         <td>02 Jul 2020</td>
346         <td><a href="/samba/ftp/patches/security/samba-4.12.3-security-2020-07-02.patch">
347         patch for Samba 4.12.3</a><br />
348         <a href="/samba/ftp/patches/security/samba-4.11.10-security-2020-07-02.patch">
349         patch for Samba 4.11.10</a><br />
350         <a href="/samba/ftp/patches/security/samba-4.10.16-security-2020-07-02.patch">
351         patch for Samba 4.10.16</a><br />
352         </td>
353         <td>CVE-2020-10730, CVE-2020-10745, CVE-2020-10760 and CVE-2020-14303.
354             Please see announcements for details.
355         </td>
356         <td>Please refer to the advisories.</td>
357         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10730">CVE-2020-10730</a>,
358         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10745">CVE-2020-10745</a>,
359         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10760">CVE-2020-10760</a>,
360         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14303">CVE-2020-14303</a>.
361         </td>
362         <td><a href="/samba/security/CVE-2020-10730.html">Announcement</a>,
363         <a href="/samba/security/CVE-2020-10745.html">Announcement</a>,
364         <a href="/samba/security/CVE-2020-10760.html">Announcement</a>,
365         <a href="/samba/security/CVE-2020-14303.html">Announcement</a>
366         </td>
367     </tr>
368
369     <tr>
370         <td>28 Apr 2020</td>
371         <td><a href="/samba/ftp/patches/security/samba-4.12.1-security-2020-04-28.patch">
372         patch for Samba 4.12.1</a><br />
373         <a href="/samba/ftp/patches/security/samba-4.11.7-security-2020-04-28.patch">
374         patch for Samba 4.11.7</a><br />
375         <a href="/samba/ftp/patches/security/samba-4.10.14-security-2020-04-28.patch">
376         patch for Samba 4.10.14</a><br />
377         </td>
378         <td>CVE-2020-10700 and CVE-2020-10704. Please see announcements for
379         details.
380         </td>
381         <td>Please refer to the advisories.</td>
382         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10700">CVE-2020-10700</a>,
383         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10704">CVE-2020-10704</a>.
384         </td>
385         <td><a href="/samba/security/CVE-2020-10700.html">Announcement</a>,
386         <a href="/samba/security/CVE-2020-10704.html">Announcement</a>
387         </td>
388     </tr>
389
390     <tr>
391         <td>21 Jan 2020</td>
392         <td><a href="/samba/ftp/patches/security/samba-4.11.4-security-2020-01-21.patch">
393         patch for Samba 4.11.4</a><br />
394         <a href="/samba/ftp/patches/security/samba-4.10.11-security-2020-01-21.patch">
395         patch for Samba 4.10.11</a><br />
396         <a href="/samba/ftp/patches/security/samba-4.9.17-security-2020-01-21.patch">
397         patch for Samba 4.9.17</a><br />
398         </td>
399         <td>CVE-2019-14902, CVE-2019-14907 and CVE-2019-19344. Please see announcements for
400         details.
401         </td>
402         <td>Please refer to the advisories.</td>
403         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14902">CVE-2019-14902</a>,
404         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14907">CVE-2019-14907</a>,
405         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19344">CVE-2019-19344.</a>.
406         </td>
407         <td><a href="/samba/security/CVE-2019-14902.html">Announcement</a>,
408         <a href="/samba/security/CVE-2019-14907.html">Announcement</a>,
409         <a href="/samba/security/CVE-2019-19344.html">Announcement</a>
410         </td>
411     </tr>
412
413     <tr>
414         <td>10 Dec 2019</td>
415         <td><a
416 href="/samba/ftp/patches/security/samba-4.11.2-security-2019-12-10.patch">
417         patch for Samba 4.11.2</a><br />
418         <a href="/samba/ftp/patches/security/samba-4.10.10-security-2019-12-10.patch">
419         patch for Samba 4.10.10</a><br />
420         <a href="/samba/ftp/patches/security/samba-4.9.16-security-2019-12-10.patch">
421         patch for Samba 4.9.16</a><br />
422         </td>
423         <td>CVE-2019-14861 and CVE-2019-14870. Please see announcements for
424         details.
425         </td>
426         <td>All versions since Samba 4.0</td>
427         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14861">CVE-2019-14861</a>,
428         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14870">CVE-2019-14870</a>.
429         </td>
430         <td><a href="/samba/security/CVE-2019-14861.html">Announcement</a>,
431         <a href="/samba/security/CVE-2019-14870.html">Announcement</a>
432         </td>
433     </tr>
434
435     <tr>
436         <td>29 Oct 2019</td>
437         <td><a href="/samba/ftp/patches/security/samba-4.11.1-security-2019-10-29.patch">
438         patch for Samba 4.11.1</a><br />
439         <a href="/samba/ftp/patches/security/samba-4.10.9-security-2019-10-29.patch">
440         patch for Samba 4.10.9</a><br />
441         <a href="/samba/ftp/patches/security/samba-4.9.14-security-2019-10-29.patch">
442         patch for Samba 4.9.14</a><br />
443         </td>
444         <td>CVE-2019-10218, CVE-2019-14833 and CVE-2019-14847. Please see
445         announcements for details.
446         </td>
447         <td>please refer to the advisories</td>
448         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10218">CVE-2019-10218</a>,
449         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14833">CVE-2019-14833</a>,
450         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14847">CVE-2019-14847</a>
451         </td>
452         <td><a href="/samba/security/CVE-2019-10218.html">Announcement</a>,
453         <a href="/samba/security/CVE-2019-14833.html">Announcement</a>,
454         <a href="/samba/security/CVE-2019-14847.html">Announcement</a>
455         </td>
456     </tr>
457
458     <tr>
459         <td>03 Sep 2019</td>
460         <td><a href="/samba/ftp/patches/security/samba-4.10.7-CVE-2019-10197.patch">
461         patch for Samba 4.10.7</a><br />
462         <a href="/samba/ftp/patches/security/samba-4.9.12-CVE-2019-10197.patch">
463         patch for Samba 4.9.12</a><br />
464         </td>
465         <td>Combination of parameters and permissions can allow user to escape
466             from the share path definition.
467         </td>
468         <td>All versions between Samba 4.9.0 and 4.9.12/4.10.7 (incl.).</td>
469         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10197">CVE-2019-10197</a>
470         </td>
471         <td><a href="/samba/security/CVE-2019-10197.html">Announcement</a>
472         </td>
473     </tr>
474
475     <tr>
476         <td>19 Jun 2019</td>
477         <td><a href="/samba/ftp/patches/security/samba-4.10.4-security-2019-06-19.patch">
478         patch for Samba 4.10.4 (both CVEs)</a><br />
479         <a href="/samba/ftp/patches/security/samba-4.9.8-security-2019-06-19.patch">
480         patch for Samba 4.9.8 (CVE-2019-12435 only)</a><br />
481         </td>
482         <td>CVE-2019-12435 and CVE-2019-12436. Please see the announcements for details.
483         </td>
484         <td>please refer to the advisories</td>
485         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12435">CVE-2019-12435</a>,
486         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12436">CVE-2019-12436</a>
487         </td>
488         <td><a href="/samba/security/CVE-2019-12435.html">Announcement</a>,
489         <a href="/samba/security/CVE-2019-12436.html">Announcement</a>
490         </td>
491     </tr>
492
493     <tr>
494         <td>14 May 2019</td>
495         <td><a href="/samba/ftp/patches/security/samba-4.10.2-security-2019-05-14.patch">
496         patch for Samba 4.10.2</a><br />
497         <a href="/samba/ftp/patches/security/samba-4.9.7-security-2019-05-14.patch">
498         patch for Samba 4.9.7</a><br />
499         <a href="/samba/ftp/patches/security/samba-4.8.11-security-2019-05-14.patch">
500         patch for Samba 4.8.11</a><br />
501         </td>
502         <td>CVE-2018-16860. Please see the announcements for details.
503         </td>
504         <td>All versions of Samba prior to 4.10.3, 4.9.8, 4.8.12.</td>
505         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16860">CVE-2018-16860</a>
506         </td>
507         <td><a href="/samba/security/CVE-2018-16860.html">Announcement</a>
508         </td>
509     </tr>
510
511     <tr>
512         <td>08 Apr 2019</td>
513         <td><a href="/samba/ftp/patches/security/samba-4.10.1-security-2019-04-08.patch">
514         patch for Samba 4.10.1 (both CVEs)</a><br />
515         <a href="/samba/ftp/patches/security/samba-4.9.5-security-2019-04-08.patch">
516         patch for Samba 4.9.5 (both CVEs)</a><br />
517         <a href="/samba/ftp/patches/security/samba-4.8.10-security-2019-04-08.patch">
518         patch for Samba 4.8.10 (CVE-2019-3880 only)</a><br />
519         </td>
520         <td>CVE-2019-3870 and CVE-2019-3880. Please see the announcements for details.
521         </td>
522         <td>please refer to the advisories</td>
523         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3870">CVE-2019-3870</a>,
524             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3880">CVE-2019-3880</a>
525         </td>
526         <td><a href="/samba/security/CVE-2019-3870.html">Announcement</a>,
527             <a href="/samba/security/CVE-2019-3880.html">Announcement</a>
528         </td>
529     </tr>
530
531     <tr>
532         <td>27 Nov 2018</td>
533         <td><a href="/samba/ftp/patches/security/samba-4.9.2-security-2018-11-27.patch">
534         patch for Samba 4.9.2 (all CVEs)</a><br />
535         <a href="/samba/ftp/patches/security/samba-4.8.6-security-2018-11-27.patch">
536         patch for Samba 4.8.6 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
537         <a href="/samba/ftp/patches/security/samba-4.7.11-security-2018-11-27.patch">
538         patch for Samba 4.7.11 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
539         <td>Numerous CVEs. Please see the announcements for details.
540         </td>
541         <td>please refer to the advisories</td>
542         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14629">CVE-2018-14629</a>,
543             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16841">CVE-2018-16841</a>,
544             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16851">CVE-2018-16851</a>,
545             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16852">CVE-2018-16852</a>,
546             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16853">CVE-2018-16853</a>,
547             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16857">CVE-2018-16857</a>
548         </td>
549         <td><a href="/samba/security/CVE-2018-14629.html">Announcement</a>,
550             <a href="/samba/security/CVE-2018-16841.html">Announcement</a>,
551             <a href="/samba/security/CVE-2018-16851.html">Announcement</a>,
552             <a href="/samba/security/CVE-2018-16852.html">Announcement</a>,
553             <a href="/samba/security/CVE-2018-16853.html">Announcement</a>,
554             <a href="/samba/security/CVE-2018-16857.html">Announcement</a>
555         </td>
556     </tr>
557
558     <tr>
559         <td>14 Aug 2018</td>
560         <td><a href="/samba/ftp/patches/security/samba-4.8.3-security-2018-08-14.patch">
561         patch for Samba 4.8.3 (all CVEs)</a><br />
562         <a href="/samba/ftp/patches/security/samba-4.7.8-security-2018-08-14.patch">
563         patch for Samba 4.7.8 (all CVEs except CVE-2018-1140)</a><br />
564         <a href="/samba/ftp/patches/security/samba-4.6.15-security-2018-08-14.patch">
565         patch for Samba 4.6.15 (CVE-2018-10858 and CVE-2018-10919)</a><br />
566         <td>Numerous CVEs. Please see the announcements for details.
567         </td>
568         <td>please refer to the advisories</td>
569         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10858">CVE-2018-10858</a>,
570             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10918">CVE-2018-10918</a>,
571             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10919">CVE-2018-10919</a>,
572             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1139">CVE-2018-1139</a>,
573             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1140">CVE-2018-1140</a>
574         </td>
575         <td><a href="/samba/security/CVE-2018-10858.html">Announcement</a>,
576             <a href="/samba/security/CVE-2018-10918.html">Announcement</a>,
577             <a href="/samba/security/CVE-2018-10919.html">Announcement</a>,
578             <a href="/samba/security/CVE-2018-1139.html">Announcement</a>,
579             <a href="/samba/security/CVE-2018-1140.html">Announcement</a>
580         </td>
581     </tr>
582
583     <tr>
584         <td>13 Mar 2018</td>
585         <td><a href="/samba/ftp/patches/security/samba-4.7.5-security-2018-03-13.patch">
586         patch for Samba 4.7.5</a><br />
587         <a href="/samba/ftp/patches/security/samba-4.6.13-security-2018-03-13.patch">
588         patch for Samba 4.6.13</a><br />
589         <a href="/samba/ftp/patches/security/samba-4.5.15-security-2018-03-13.patch">
590         patch for Samba 4.5.15</a><br />
591         <a href="/samba/ftp/patches/security/samba-4.4.16-CVE-2018-1057.patch">
592         patch for Samba 4.4.16 (only CVE-2018-1057)</a><br />
593         <a href="/samba/ftp/patches/security/samba-4.3.13-CVE-2018-1057.patch">
594         patch for Samba 4.3.13 (only CVE-2018-1057)</a><br />
595         <td>Numerous CVEs. Please see the announcements for details.
596         </td>
597         <td>please refer to the advisories</td>
598         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1050">CVE-2018-1050</a>,
599             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1057">CVE-2018-1057</a>
600         </td>
601         <td><a href="/samba/security/CVE-2018-1050.html">Announcement</a>, 
602             <a href="/samba/security/CVE-2018-1057.html">Announcement</a>
603         </td>
604     </tr>
605
606     <tr>
607         <td>21 Nov 2017</td>
608         <td><a href="/samba/ftp/patches/security/samba-4.7.2-security-2017-11-21.patch">
609         patch for Samba 4.7.2</a><br />
610         <a href="/samba/ftp/patches/security/samba-4.6.10-security-2017-11-21.patch">
611         patch for Samba 4.6.10</a><br />
612         <a href="/samba/ftp/patches/security/samba-4.5.14-security-2017-11-21.patch">
613         patch for Samba 4.5.14</a><br />
614         <td>Numerous CVEs. Please see the announcements for details.
615         </td>
616         <td>please refer to the advisories</td>
617         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14746">CVE-2017-14746</a>, 
618             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15275">CVE-2017-15275</a>
619         </td>
620         <td><a href="/samba/security/CVE-2017-14746.html">Announcement</a>, 
621             <a href="/samba/security/CVE-2017-15275.html">Announcement</a>
622         </td>
623     </tr>
624
625     <tr>
626         <td>20 Sep 2017</td>
627         <td><a href="/samba/ftp/patches/security/samba-4.6.7-security-2017-09-20.patch">
628         patch for Samba 4.6.7</a><br />
629         <a href="/samba/ftp/patches/security/samba-4.5.13-security-2017-09-20.patch">
630         patch for Samba 4.5.13</a><br />
631         <a href="/samba/ftp/patches/security/samba-4.4.15-security-2017-09-20.patch">
632         patch for Samba 4.4.15</a><br />
633         <td>Numerous CVEs. Please see the announcements for details.
634         </td>
635         <td>please refer to the advisories</td>
636         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12150">CVE-2017-12150</a>, 
637             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12151">CVE-2017-12151</a>, 
638             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12163">CVE-2017-12163</a>
639         </td>
640         <td><a href="/samba/security/CVE-2017-12150.html">Announcement</a>, 
641             <a href="/samba/security/CVE-2017-12151.html">Announcement</a>, 
642             <a href="/samba/security/CVE-2017-12163.html">Announcement</a>
643         </td>
644     </tr>
645
646     <tr>
647         <td>12 July 2017</td>
648         <td><a href="/samba/ftp/patches/security/samba-4.x.y-CVE-2017-11103.patch">
649         patch for Samba 4.x.y</a><br />
650         <td>Orpheus&apos; Lyre mutual authentication validation bypass.
651         </td>
652         <td>All versions between Samba 4.0.0 and 4.6.6/4.5.12/4.4.15</td>
653         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11103">CVE-2017-11103</a>
654         </td>
655         <td><a href="/samba/security/CVE-2017-11103.html">Announcement</a>
656         </td>
657     </tr>
658
659     <tr>
660         <td>24 May 2017</td>
661         <td><a href="/samba/ftp/patches/security/samba-4.6.3-4.5.9-4.4.13-CVE-2017-7494.patch">
662         patch for Samba 4.6.3, 4.5.9, 4.4.13</a><br />
663         <td>Remote code execution from a writable share.
664         </td>
665         <td>All versions between Samba 3.5.0 and 4.6.4/4.5.10/4.4.14</td>
666         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7494">CVE-2017-7494</a>
667         </td>
668         <td><a href="/samba/security/CVE-2017-7494.html">Announcement</a>
669         </td>
670     </tr>
671
672     <tr>
673         <td>23 Mar 2017</td>
674         <td><a href="/samba/ftp/patches/security/samba-4.6.0-CVE-2017-2619.patch">
675         patch for Samba 4.6.0</a><br />
676         <a href="/samba/ftp/patches/security/samba-4.5.6-CVE-2017-2619.patch">
677         patch for Samba 4.5.6</a><br />
678         <a href="/samba/ftp/patches/security/samba-4.4.11-CVE-2017-2619.patch">
679         patch for Samba 4.4.11</a><br />
680         <td>Symlink race allows access outside share definition.
681         </td>
682         <td>All versions of Samba prior to 4.6.1, 4.5.7, 4.4.12</td>
683         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2619">CVE-2017-2619</a>
684         </td>
685         <td><a href="/samba/security/CVE-2017-2619.html">Announcement</a>
686         </td>
687     </tr>
688
689     <tr>
690         <td>19 Dec 2016</td>
691         <td><a href="/samba/ftp/patches/security/samba-4.5.2-security-20016-12-19.patch">
692         patch for Samba 4.5.2</a><br />
693         <a href="/samba/ftp/patches/security/samba-4.4.7-security-20016-12-19.patch">
694         patch for Samba 4.4.7</a><br />
695         <a href="/samba/ftp/patches/security/samba-4.3.12-security-20016-12-19.patch">
696         patch for Samba 4.3.12</a><br />
697         <td>Numerous CVEs. Please see the announcements for details.
698         </td>
699         <td>please refer to the advisories</td>
700         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2123">CVE-2016-2123</a>, 
701             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2125">CVE-2016-2125</a>, 
702             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2126">CVE-2016-2126</a>
703         </td>
704         <td><a href="/samba/security/CVE-2016-2123.html">Announcement</a>, 
705             <a href="/samba/security/CVE-2016-2125.html">Announcement</a>, 
706             <a href="/samba/security/CVE-2016-2126.html">Announcement</a>
707         </td>
708     </tr>
709
710     <tr>
711         <td>07 Jul 2016</td>
712         <td><a href="/samba/ftp/patches/security/samba-4.4.4-CVE-2016-2119.patch">
713         patch for Samba 4.4.4</a><br />
714         <a href="/samba/ftp/patches/security/samba-4.3.10-CVE-2016-2119.patch">
715         patch for Samba 4.3.10</a><br />
716         <a href="/samba/ftp/patches/security/samba-4.2.13-CVE-2016-2119.patch">
717         patch for Samba 4.2.13</a><br />
718         <td>Client side SMB2/3 required signing can be downgraded.
719         </td>
720         <td>4.0.0 - 4.4.4</td>
721         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2119">CVE-2016-2119</a>
722         </td>
723         <td><a href="/samba/security/CVE-2016-2119.html">Announcement</a>
724         </td>
725     </tr>
726
727     <tr>
728         <td>12 Apr 2016</td>
729         <td><a href="/samba/ftp/patches/security/samba-4.4.0-security-2016-04-12-final.patch">
730         patch for Samba 4.4.0</a><br />
731         <a href="/samba/ftp/patches/security/samba-4.3.6-security-2016-04-12-final.patch">
732         patch for Samba 4.3.6</a><br />
733         <a href="/samba/ftp/patches/security/samba-4.2.9-security-2016-04-12-final.patch">
734         patch for Samba 4.2.9</a><br />
735         <a href="/samba/ftp/patches/security/samba-v4-0-security-2016-04-12-fileserver-only.patch.xz">
736         patch for Samba 4.0.26 (fileserver only! no client! no domain controller!)</a><br />
737         <a href="/samba/ftp/patches/security/samba-v3-6-security-2016-04-12.tar.xz">
738         patch for Samba 3.6.25 (only related CVEs)</a><br />
739         <td>Numerous CVEs. Please see the announcements for details.
740         </td>
741         <td>please refer to the advisories</td>
742         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5370">CVE-2015-5370</a>, 
743             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2110">CVE-2016-2110</a>, 
744             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2111">CVE-2016-2111</a>, 
745             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2112">CVE-2016-2112</a>, 
746             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2113">CVE-2016-2113</a>, 
747             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2114">CVE-2016-2114</a>, 
748             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2115">CVE-2016-2115</a>, 
749             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2118">CVE-2016-2118</a>
750         </td>
751         <td><a href="/samba/security/CVE-2015-5370.html">Announcement</a>
752             <a href="/samba/security/CVE-2016-2110.html">Announcement</a>
753             <a href="/samba/security/CVE-2016-2111.html">Announcement</a>
754             <a href="/samba/security/CVE-2016-2112.html">Announcement</a>
755             <a href="/samba/security/CVE-2016-2113.html">Announcement</a>
756             <a href="/samba/security/CVE-2016-2114.html">Announcement</a>
757             <a href="/samba/security/CVE-2016-2115.html">Announcement</a>
758             <a href="/samba/security/CVE-2016-2118.html">Announcement</a>
759         </td>
760     </tr>
761
762     <tr>
763         <td>08 Mar 2016</td>
764         <td><a href="/samba/ftp/patches/security/samba-4.3.5-security-2016-03-08.patch">
765         patch for Samba 4.3.5</a><br />
766         <a href="/samba/ftp/patches/security/samba-4.2.8-security-2016-03-08.patch">
767         patch for Samba 4.2.8</a><br />
768         <a href="/samba/ftp/patches/security/samba-4.1.22-security-2016-03-08.patch">
769         patch for Samba 4.1.22</a><br />
770         <td>Incorrect ACL get/set allowed on symlink path, Out-of-bounds read in internal DNS server.
771         </td>
772         <td>please refer to the advisories</td>
773         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7560">CVE-2015-7560</a>, 
774             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0771">CVE-2016-0771</a>, 
775         </td>
776         <td><a href="/samba/security/CVE-2015-7560.html">Announcement</a>
777             <a href="/samba/security/CVE-2016-0771.html">Announcement</a>
778         </td>
779     </tr>
780
781     <tr>
782         <td>16 Dec 2015</td>
783         <td><a href="/samba/ftp/patches/security/samba-4.3.2-security-2015-12-16.patch">
784         patch for Samba 4.3.2</a><br />
785         <a href="/samba/ftp/patches/security/samba-4.2.6-security-2015-12-16.patch">
786         patch for Samba 4.2.6</a><br />
787         <a href="/samba/ftp/patches/security/samba-4.1.21-security-2015-12-16.patch">
788         patch for Samba 4.1.21</a><br />
789         <a href="/samba/ftp/patches/security/samba-3.6.25-security-2015-12-16.patch">
790         patch for Samba 3.6.25</a><br />
791         <td>Numerous CVEs. Please see the announcements for details.
792         </td>
793         <td>3.0.0 to 4.3.2</td>
794         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3223">CVE-2015-3223</a>, 
795             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5252">CVE-2015-5252</a>, 
796             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5296">CVE-2015-5296</a>, 
797             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5299">CVE-2015-5299</a>, 
798             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5330">CVE-2015-5330</a>, 
799             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7540">CVE-2015-7540</a>, 
800             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8467">CVE-2015-8467</a>
801         </td>
802         <td><a href="/samba/security/CVE-2015-3223.html">Announcement</a>
803             <a href="/samba/security/CVE-2015-5252.html">Announcement</a>
804             <a href="/samba/security/CVE-2015-5296.html">Announcement</a>
805             <a href="/samba/security/CVE-2015-5299.html">Announcement</a>
806             <a href="/samba/security/CVE-2015-5330.html">Announcement</a>
807             <a href="/samba/security/CVE-2015-7540.html">Announcement</a>
808             <a href="/samba/security/CVE-2015-8467.html">Announcement</a>
809         </td>
810     </tr>
811
812     <tr>
813         <td>23 Feb 2015</td>
814         <td><a href="/samba/ftp/patches/security/samba-4.1.16-CVE-2015-0240.patch">
815         patch for Samba 4.1.16</a><br />
816         <a href="/samba/ftp/patches/security/samba-4.0.24-CVE-2015-0240.patch">
817         patch for Samba 4.0.24</a><br />
818         <a href="/samba/ftp/patches/security/samba-3.6.24-CVE-2015-0240.patch">
819         patch for Samba 3.6.24</a><br />
820         <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2015-0240.patch">
821         patch for Samba 3.5.22</a><br />
822         <td>Unexpected code execution in smbd.
823         </td>
824         <td>3.5.0 - 4.2.0rc4</td>
825         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0240">CVE-2015-0240</a>
826         </td>
827         <td><a href="/samba/security/CVE-2015-0240.html">Announcement</a>
828         </td>
829     </tr>
830
831     <tr>
832         <td>15 Jan 2015</td>
833         <td><a href="/samba/ftp/patches/security/samba-4.1.15-CVE-2014-8143.patch">
834         patch for Samba 4.1.15</a><br />
835         <a href="/samba/ftp/patches/security/samba-4.0.23-CVE-2014-8143.patch">
836         patch for Samba 4.0.23</a><br />
837         <td>Elevation of privilege to Active Directory Domain Controller.
838         </td>
839         <td>4.0.0 - 4.1.15</td>
840         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8143">CVE-2014-8143</a>
841         </td>
842         <td><a href="/samba/security/CVE-2014-8143.html">Announcement</a>
843         </td>
844     </tr>
845
846     <tr>
847         <td>01 Aug 2014</td>
848         <td><a href="/samba/ftp/patches/security/samba-4.1.10-CVE-2014-3560.patch">
849         patch for Samba 4.1.10</a><br />
850         <a href="/samba/ftp/patches/security/samba-4.0.20-CVE-2014-3560.patch">
851         patch for Samba 4.0.20</a><br />
852         <td>Remote code execution in nmbd.
853         </td>
854         <td>4.0.0 - 4.1.10</td>
855         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3560">CVE-2014-3560</a>
856         </td>
857         <td><a href="/samba/security/CVE-2014-3560.html">Announcement</a>
858         </td>
859     </tr>
860
861     <tr>
862         <td>23 Jun 2014</td>
863         <td><a href="/samba/ftp/patches/security/samba-4.1.8-CVE-2014-0244-CVE-2014-3493.patch">
864         patch for Samba 4.1.8</a><br />
865         <a href="/samba/ftp/patches/security/samba-4.0.18-CVE-2014-0244-CVE-2014-3493.patch">
866         patch for Samba 4.0.18</a><br />
867         <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0244-CVE-2014-3493.patch">
868         patch for Samba 3.6.23</a><br />
869         <td>Denial of service - CPU loop, Denial of service - Server crash/memory corruption.
870         </td>
871         <td>please refer to the advisories</td>
872         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0244">CVE-2014-0244</a>, 
873             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3493">CVE-2014-3493</a>
874         </td>
875         <td><a href="/samba/security/CVE-2014-0244.html">Announcement</a>
876             <a href="/samba/security/CVE-2014-3493.html">Announcement</a>
877         </td>
878     </tr>
879
880     <tr>
881         <td>03 June 2014</td>
882         <td><a href="/samba/ftp/patches/security/samba-4.0.17-CVE-2014-0178-CVE-2014-0239.patch">
883         patch for Samba 4.0.17</a><br />
884         <a href="/samba/ftp/patches/security/samba-4.1.7-CVE-2014-0178-CVE-2014-0239.patch">
885         patch for Samba 4.1.7</a><br />
886         <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0178.patch">
887         patch for Samba 3.6.23 (CVE-2014-0178 only)</a><br />
888         <td>Uninitialized memory exposure, Potential DOS in Samba internal DNS server.
889         </td>
890         <td>please refer to the advisories</td>
891         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0178">CVE-2014-0178</a>, 
892             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0239">CVE-2014-0239</a>
893         </td>
894         <td><a href="/samba/security/CVE-2014-0178.html">Announcement</a>
895             <a href="/samba/security/CVE-2014-0239.html">Announcement</a>
896         </td>
897     </tr>
898
899     <tr>
900         <td>11 Mar 2014</td>
901         <td><a href="/samba/ftp/patches/security/samba-4.1.5-CVE-2013-4496-CVE-2013-6442.patch">
902         patch for Samba 4.1.5</a><br />
903         <a href="/samba/ftp/patches/security/samba-4.0.15-CVE-2013-4496-CVE-2013-6442.patch">
904         patch for Samba 4.0.15</a><br />
905         <a href="/samba/ftp/patches/security/samba-3.6.22-CVE-2013-4496.patch">
906         patch for Samba 3.6.22</a><br />
907         <td>Password lockout not enforced for SAMR password changes, smbcacls can remove a file
908         or directory ACL by mistake.
909         </td>
910         <td>please refer to the advisories</td>
911         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496">CVE-2013-4496</a>, 
912             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6442">CVE-2013-6442</a>
913         </td>
914         <td><a href="/samba/security/CVE-2013-4496.html">Announcement</a>
915             <a href="/samba/security/CVE-2013-6442.html">Announcement</a>
916         </td>
917     </tr>
918
919     <tr>
920         <td>09 Dec 2013</td>
921         <td><a href="/samba/ftp/patches/security/samba-4.1.2-CVE-2013-4408-CVE-2012-6150.patch">
922         patch for Samba 4.1.2</a><br />
923         <a href="/samba/ftp/patches/security/samba-4.0.12-CVE-2013-4408-CVE-2012-6150.patch">
924         patch for Samba 4.0.12</a><br />
925         <a href="/samba/ftp/patches/security/samba-3.6.21-CVE-2013-4408-CVE-2012-6150.patch">
926         patch for Samba 3.6.21</a><br />
927         <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2013-4408.patch">
928         patch for Samba 3.5.22</a><br />
929         <a href="/samba/ftp/patches/security/samba-3.4.17-CVE-2013-4408.patch">
930         patch for Samba 3.4.17</a>
931         <td>DCE-RPC fragment length field is incorrectly checked, pam_winbind
932         login without require_membership_of restrictions.</td>
933         <td>please refer to the advisories</td>
934         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408">CVE-2013-4408</a>, 
935             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150">CVE-2012-6150</a>
936         </td>
937         <td><a href="/samba/security/CVE-2013-4408.html">Announcement</a>
938             <a href="/samba/security/CVE-2012-6150.html">Announcement</a>
939         </td>
940     </tr>
941
942     <tr>
943         <td>11 Nov 2013</td>
944         <td><a href="/samba/ftp/patches/security/samba-4.1.0-CVE-2013-4475-CVE-2013-4476.patch">
945         patch for Samba 4.1.0</a><br />
946         <a href="/samba/ftp/patches/security/samba-4.0.10-CVE-2013-4475-CVE-2013-4476.patch">
947         patch for Samba 4.0.10</a><br />
948         <a href="/samba/ftp/patches/security/samba-3.6.19-CVE-2013-4475.patch">
949         patch for Samba 3.6.19</a><br />
950         <td>ACLs are not checked on opening an alternate data stream on a file
951             or directory, Private key in key.pem world readable.</td>
952         <td>3.2.0 - 4.1.0, 4.0.0 - 4.0.10, 4.1.0</td>
953         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475">CVE-2013-4475</a>, 
954             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4476">CVE-2013-4476</a>
955         </td>
956         <td><a href="/samba/security/CVE-2013-4475.html">Announcement</a>
957             <a href="/samba/security/CVE-2013-4476.html">Announcement</a>
958         </td>
959     </tr>
960
961     <tr>
962         <td>05 Aug 2013</td>
963         <td><a href="/samba/ftp/patches/security/samba-4.0.7-CVE-2013-4124.patch">
964         patch for Samba 4.0.7</a><br />
965         <a href="/samba/ftp/patches/security/samba-3.6.16-CVE-2013-4124.patch">
966         patch for Samba 3.6.16</a><br />
967         <a href="/samba/ftp/patches/security/samba-3.5.21-CVE-2013-4124.patch">
968         patch for Samba 3.5.21</a><br />
969         <td>Denial of service - CPU loop and memory allocation.</td>
970         <td>3.0.x-4.0.7</td>
971         <td><a
972         href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124">CVE-2013-4124</a>
973         </td>
974         <td><a href="/samba/security/CVE-2013-4124.html">Announcement</a>
975         </td>
976     </tr>
977
978     <tr>
979         <td>02 Apr 2013</td>
980         <td><a href="/samba/ftp/patches/security/samba-3.6-CVE-2013-0454.patch">
981         patch for Samba 3.6.5</a>
982         <td>A writable configured share might get read only</td>
983         <td>3.6.0 - 3.6.5 (inclusive)</td>
984         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0454">CVE-2013-0454</a>
985         </td>
986         <td><a href="/samba/security/CVE-2013-0454.html">Announcement</a>
987         </td>
988     </tr>
989
990     <tr>
991         <td>19 Mar 2013</td>
992         <td><a href="/samba/ftp/patches/security/samba-4.0.3-CVE-2013-1863.patch">
993         patch for Samba 4.0.3</a>
994         <td>World-writeable files may be created in additional shares on a Samba
995         4.0 AD DC.</td>
996         <td>4.0.0rc6-4.0.3</td>
997         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1863">CVE-2013-1863</a>
998         </td>
999         <td><a href="/samba/security/CVE-2013-1863.html">Announcement</a>
1000         </td>
1001     </tr>
1002
1003     <tr>
1004         <td>30 Jan 2013</td>
1005         <td><a href="/samba/ftp/patches/security/samba-4.0.1-CVE-2013-0213-CVE-2013-0214.patch">
1006         patch for Samba 4.0.1</a><br />
1007         <a href="/samba/ftp/patches/security/samba-3.6.11-CVE-2013-0213-CVE-2013-0214.patch">
1008         patch for Samba 3.6.11</a><br />
1009         <a href="/samba/ftp/patches/security/samba-3.5.20-CVE-2013-0213-CVE-2013-0214.patch">
1010         patch for Samba 3.5.20</a><br />
1011         <td>Clickjacking issue and potential XSRF in SWAT.</td>
1012         <td>3.0.x-4.0.1</td>
1013         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213">CVE-2013-0213</a>, 
1014             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214">CVE-2013-0214</a>
1015         </td>
1016         <td><a href="/samba/security/CVE-2013-0213.html">Announcement</a>
1017             <a href="/samba/security/CVE-2013-0214.html">Announcement</a>
1018         </td>
1019     </tr>
1020
1021     <tr>
1022         <td>15 Jan 2013</td>
1023         <td><a href="/samba/ftp/patches/security/samba-4.0.0-CVE-2013-0172.patch">
1024         patch for Samba 4.0.0</a>
1025         <td>Samba 4.0 as an AD DC may provide authenticated users with write
1026         access to LDAP directory objects.</td>
1027         <td>4.0.0</td>
1028         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0172">CVE-2013-0172</a></td>
1029         <td><a href="/samba/security/CVE-2013-0172.html">Announcement</a></td>
1030     </tr>
1031
1032     <tr>
1033         <td>30 Apr 2012</td>
1034         <td><a href="/samba/ftp/patches/security/samba-3.4.16-CVE-2012-2111.patch">
1035         patch for Samba 3.4.16</a><br />
1036         <a href="/samba/ftp/patches/security/samba-3.5.14-CVE-2012-2111.patch">
1037         patch for Samba 3.5.14</a><br />
1038         <a href="/samba/ftp/patches/security/samba-3.6.4-CVE-2012-2111.patch">
1039         patch for Samba 3.6.4</a><br />
1040         <td>Incorrect permission checks when granting/removing privileges can
1041         compromise file server security.</td>
1042         <td>3.4.x-3.6.4</td>
1043         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2111">CVE-2012-2111</a></td>
1044         <td><a href="/samba/security/CVE-2012-2111.html">Announcement</a></td>
1045     </tr>
1046
1047     <tr>
1048         <td>10 Apr 2012</td>
1049         <td><a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2012-1182.patch">
1050         patch for Samba 3.0.37</a><br />
1051         <a href="/samba/ftp/patches/security/samba-3.2.15-CVE-2012-1182.patch">
1052         patch for Samba 3.2.15</a><br />
1053         <a href="/samba/ftp/patches/security/samba-3.3.16-CVE-2012-1182.patch">
1054         patch for Samba 3.3.16</a><br />
1055         <a href="/samba/ftp/patches/security/samba-3.4.15-CVE-2012-1182.patch">
1056         patch for Samba 3.4.15</a><br />
1057         <a href="/samba/ftp/patches/security/samba-3.5.13-CVE-2012-1182.patch">
1058         patch for Samba 3.5.13</a><br />
1059         <a href="/samba/ftp/patches/security/samba-3.6.3-CVE-2012-1182.patch">
1060         patch for Samba 3.6.3</a><br />
1061         <td>"root" credential remote code execution</td>
1062         <td>all current releases</td>
1063         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182">CVE-2012-1182</a></td>
1064         <td><a href="/samba/security/CVE-2012-1182.html">Announcement</a></td>
1065     </tr>
1066
1067     <tr>
1068         <td>23 Feb 2012</td>
1069         <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2012-0870.patch">
1070         patch for Samba 3.0</a><br />
1071         <a href="/samba/ftp/patches/security/samba-3.2-CVE-2012-0870.patch">
1072         patch for Samba 3.2</a><br />
1073         <a href="/samba/ftp/patches/security/samba-3.3-CVE-2012-0870.patch">
1074         patch for Samba 3.3</a><br />
1075         <td>Remote code execution vulnerability in smbd</td>
1076         <td>pre-3.4</td>
1077         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0870">CVE-2012-0870</a></td>
1078         <td><a href="/samba/security/CVE-2012-0870.html">Announcement</a></td>
1079     </tr>
1080
1081     <tr>
1082         <td>29 Jan 2012</td>
1083         <td><a href="/samba/ftp/patches/security/samba-3.6.2-CVE-2012-0817.patch">
1084         patch for Samba 3.6.2</a>
1085         <td>Memory leak/Denial of service</td>
1086         <td>3.6.0-3.6.2</td>
1087         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0817">CVE-2012-0817</a></td>
1088         <td><a href="/samba/security/CVE-2012-0817.html">Announcement</a></td>
1089     </tr>
1090
1091     <tr>
1092         <td>26 Jul 2011</td>
1093         <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2522.patch">
1094         patch for Samba 3.3.15</a><br />
1095         <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2522.patch">
1096         patch for Samba 3.4.13</a><br />
1097         <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2522.patch">
1098         patch for Samba 3.5.9</a><br />
1099         <td>Cross-Site Request Forgery in SWAT</td>
1100         <td>all current releases</td>
1101         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2522">CVE-2011-2522</a></td>
1102         <td><a href="/samba/security/CVE-2011-2522.html">Announcement</a></td>
1103     </tr>
1104
1105     <tr>
1106         <td>26 Jul 2011</td>
1107         <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2694.patch">
1108         patch for Samba 3.3.15</a><br />
1109         <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2694.patch">
1110         patch for Samba 3.4.13</a><br />
1111         <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2694.patch">
1112         patch for Samba 3.5.9</a><br />
1113         <td>Cross-Site Scripting vulnerability in SWAT</td>
1114         <td>all current releases</td>
1115         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2694">CVE-2011-2694</a></td>
1116         <td><a href="/samba/security/CVE-2011-2694.html">Announcement</a></td>
1117     </tr>
1118
1119     <tr>
1120         <td>18 Feb 2011</td>
1121         <td><a href="/samba/ftp/patches/security/samba-3.3.14-CVE-2011-0719.patch">
1122         patch for Samba 3.3.14</a><br />
1123         <a href="/samba/ftp/patches/security/samba-3.4.11-CVE-2011-0719.patch">
1124         patch for Samba 3.4.11</a><br />
1125         <a href="/samba/ftp/patches/security/samba-3.5.6-CVE-2011-0719.patch">
1126         patch for Samba 3.5.6</a><br />
1127         <td>Denial of service - memory corruption</td>
1128         <td>all current releases</td>
1129         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0719">CVE-2011-0719</a></td>
1130         <td><a href="/samba/security/CVE-2011-0719.html">Announcement</a></td>
1131     </tr>
1132
1133     <tr>
1134         <td>14 Sep 2010</td>
1135         <td><a href="/samba/ftp/patches/security/samba-3.3.13-CVE-2010-3069.patch">
1136         patch for Samba 3.3.13</a><br />
1137         <a href="/samba/ftp/patches/security/samba-3.4.8-CVE-2010-3069.patch">
1138         patch for Samba 3.4.8</a><br />
1139         <a href="/samba/ftp/patches/security/samba-3.5.4-CVE-2010-3069.patch">
1140         patch for Samba 3.5.4</a><br />
1141         <td>Buffer Overrun Vulnerability</td>
1142         <td>all current releases</td>
1143         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3069">CVE-2010-3069</a></td>
1144         <td><a href="/samba/security/CVE-2010-3069.html">Announcement</a></td>
1145     </tr>
1146
1147     <tr>
1148         <td>16 Jun 2010</td>
1149         <td><a href="/samba/ftp/patches/security/samba-3.3.12-CVE-2010-2063.patch">
1150         patch for Samba 3.3.12 and 3.2.15</a><br />
1151         <a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2010-2063.patch">
1152         patch for Samba 3.0.37</a><br />
1153         <td>Memory Corruption Vulnerability</td>
1154         <td>3.0.x, 3.2.x, 3.3.0-3.3.12</td>
1155         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-CVE-2010-2063">CVE-2010-2063</a></td>
1156         <td><a href="/samba/security/CVE-2010-2063.html">Announcement</a></td>
1157     </tr>
1158
1159     <tr>
1160         <td>08 Mar 2010</td>
1161         <td><a href="/samba/ftp/patches/security/samba-3.5.0-CVE-2010-0728.patch">
1162         patch for Samba 3.5.0</a><br />
1163         <a href="/samba/ftp/patches/security/samba-3.4.6-CVE-2010-0728.patch">
1164         patch for Samba 3.4.6</a><br />
1165         <a href="/samba/ftp/patches/security/samba-3.3.11-CVE-2010-0728.patch">
1166         patch for Samba 3.3.11</a><br />
1167         <td>Permission ignored</td>
1168         <td>3.3.11, 3.4.6, 3.5.0</td>
1169         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0728">CVE-2010-0728</a></td>
1170         <td><a href="/samba/security/CVE-2010-0728.html">Announcement</a></td>
1171     </tr>
1172
1173     <tr>
1174         <td>02 Feb 2010</td>
1175                   <td>not available</td>
1176         <td>Change parameter "wide links" to default to "no"</td>
1177         <td>pre-3.4.6</td>
1178         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926">CVE-2010-0926</a></td>
1179         <td><a href="/samba/security/CVE-2010-0926.html">Announcement</a></td>
1180     </tr>
1181
1182     <tr>
1183         <td>01 Oct 2009</td>
1184         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-1.patch">
1185         patch 1 for Samba 3.4.1</a>
1186         <a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-2.patch">
1187         patch 2 for Samba 3.4.1</a>
1188         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-1.patch">
1189         patch 1 for Samba 3.3.7</a>
1190         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-2.patch">
1191         patch 2 for Samba 3.3.7</a>
1192         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-1.patch">
1193         patch 1 for Samba 3.2.14</a>
1194         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-2.patch">
1195         patch 2 for Samba 3.2.14</a>
1196         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-1.patch">
1197         patch 1 for Samba 3.0.36</a>
1198         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-2.patch">
1199         patch 2 for Samba 3.0.36</a>
1200         <td>Information disclosure by setuid mount.cifs</td>
1201         <td>all releases</td>
1202         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2948</a></td>
1203         <td><a href="/samba/security/CVE-2009-2948.html">Announcement</a></td>
1204     </tr>
1205
1206     <tr>
1207         <td>01 Oct 2009</td>
1208         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2906.patch">
1209         patch for Samba 3.4.1</a><br />
1210         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2906.patch">
1211         patch for Samba 3.3.7</a><br />
1212         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2906.patch">
1213         patch for Samba 3.2.14</a><br />
1214         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2906.patch">
1215         patch for Samba 3.0.36</a><br />
1216         <td>Remote DoS against smbd on authenticated connections</td>
1217         <td>all releases</td>
1218         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2906</a></td>
1219         <td><a href="/samba/security/CVE-2009-2906.html">Announcement</a></td>
1220     </tr>
1221     <tr>
1222
1223     <tr>
1224         <td>01 Oct 2009</td>
1225         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2813.patch">
1226         patch for Samba 3.4.1</a><br />
1227         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2813.patch">
1228         patch for Samba 3.3.7</a><br />
1229         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2813.patch">
1230         patch for Samba 3.2.14</a><br />
1231         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2813.patch">
1232         patch for Samba 3.0.36</a><br />
1233         <td>Misconfigured /etc/passwd file may share folders unexpectedly</td>
1234         <td>&gt; 3.0.11</td>
1235         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813">CVE-2009-2813</a></td>
1236         <td><a href="/samba/security/CVE-2009-2813.html">Announcement</a></td>
1237     </tr>
1238     <tr>
1239
1240     <tr>
1241         <td>23 Jun 2009</td>
1242         <td><a href="/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patch">
1243         patch for Samba 3.3.5</a><br />
1244         <a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patch">
1245         patch for Samba 3.2.12</a><br />
1246         <a href="/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patch">
1247         patch for Samba 3.0.34</a><br />
1248         <td>Uninitialized read of a data value</td>
1249         <td>Samba 3.0.31 - 3.3.5</td>
1250         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888">CVE-2009-1888</a></td>
1251         <td><a href="/samba/security/CVE-2009-1888.html">Announcement</a></td>
1252     </tr>
1253     <tr>
1254
1255     <tr>
1256         <td>23 Jun 2009</td>
1257         <td><a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1886.patch">
1258         patch for Samba 3.2.12</a>
1259         <td>Formatstring vulnerability in smbclient</td>
1260         <td>Samba 3.2.0 - 3.2.12</td>
1261         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886">CVE-2009-1886</a></td>
1262         <td><a href="/samba/security/CVE-2009-1886.html">Announcement</a></td>
1263     </tr>
1264     <tr>
1265
1266     <tr>
1267         <td>05 Jan 2009</td>
1268         <td><a href="/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch">
1269         patch for Samba 3.2.6</a>
1270         <td>Potential access to "/" in setups with registry shares enabled</td>
1271         <td>Samba 3.2.0 - 3.2.6</td>
1272         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0022">CVE-2009-0022</a></td>
1273         <td><a href="/samba/security/CVE-2009-0022.html">Announcement</a></td>
1274     </tr>
1275     <tr>
1276         <td>27 Nov 2008</td>
1277         <td><a href="/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patch">
1278         patch for Samba 3.0.32</a>
1279         <a href="/samba/ftp/patches/security/samba-3.2.4-CVE-2008-4314.patch">
1280         patch for Samba 3.2.4</a></td>
1281         <td>Potential leak of arbitrary memory contents</td>
1282         <td>Samba 3.0.29 - 3.2.4</td>
1283         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4314">CVE-2008-4314</a></td>
1284         <td><a href="/samba/security/CVE-2008-4314.html">Announcement</a></td>
1285     </tr>
1286
1287     <tr>
1288         <td>27 Aug 2008</td>
1289         <td><a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-1.patch">
1290         patch 1 for Samba 3.2.2</a> 
1291         <a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-2.patch">
1292         patch 2 for Samba 3.2.2</a></td>
1293         <td>Wrong permissions of group_mapping.ldb</td>
1294         <td>Samba 3.2.0 - 3.2.2</td>
1295         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3789">CVE-2008-3789</a></td>
1296         <td><a href="/samba/security/CVE-2008-3789.html">Announcement</a></td>
1297     </tr>
1298
1299     <tr>
1300         <td>29 May 2008</td>
1301         <td><a href="/samba/ftp/patches/security/samba-3.0.29-CVE-2008-1105.patch">patch for Samba 3.0.29</a></td>
1302         <td>Boundary failure when parsing SMB responses</td>
1303         <td>Samba 3.0.0 - 3.0.29</td>
1304         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105">CVE-2008-1105</a></td>
1305         <td><a href="/samba/security/CVE-2008-1105.html">Announcement</a></td>
1306     </tr>
1307
1308     <tr>
1309         <td>10 Dec 2007</td>
1310         <td><a href="/samba/ftp/patches/security/samba-3.0.27a-CVE-2007-6015.patch">patch for Samba 3.0.27a</a></td>
1311         <td>Remote Code Execution in Samba's nmbd (send_mailslot())</td>
1312         <td>Samba 3.0.0 - 3.0.27a</td>
1313         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6015">CVE-2007-6015</a></td>
1314         <td><a href="/samba/security/CVE-2007-6015.html">Announcement</a></td>
1315     </tr>
1316
1317     <tr>
1318         <td>15 Nov 2007</td>
1319         <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-5398.patch">patch for Samba 3.0.26a</a></td>
1320         <td>Remote Code Execution in Samba's nmbd</td>
1321         <td>Samba 3.0.0 - 3.0.26a</td>
1322         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398">CVE-2007-5398</a></td>
1323         <td><a href="/samba/security/CVE-2007-5398.html">Announcement</a></td>
1324     </tr>
1325
1326     <tr>
1327         <td>15 Nov 2007</td>
1328         <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-4572.patch">patch for Samba 3.0.26a</a></td>
1329         <td>GETDC mailslot processing buffer overrun in nmbd</td>
1330         <td>Samba 3.0.0 - 3.0.26a</td>
1331         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4572">CVE-2007-4572</a></td>
1332         <td><a href="/samba/security/CVE-2007-4572.html">Announcement</a></td>
1333     </tr>
1334
1335     <tr>
1336         <td>11 Sep 2007</td>
1337         <td><a href="/samba/ftp/patches/security/samba-3.0.25-CVE-2007-4138.patch">patch for Samba 3.0.25</a></td>
1338         <td>Incorrect primary group assignment for users using the rfc2307 or sfu nss info plugin.</td>
1339         <td>Samba 3.0.25 - 3.0.25c</td>
1340         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4138">CVE-2007-4138</a></td>
1341         <td><a href="/samba/security/CVE-2007-4138.html">Announcement</a></td>
1342     </tr>
1343
1344     <tr>
1345         <td>14 May 2007</td>
1346         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2447_v2.patch">patch for Samba 3.0.24</a></td>
1347         <td>Remote Command Injection Vulnerability (Updated June 5 to include missing &quot;c&quot; character from INCLUDE list).</td>
1348         <td>Samba 3.0.0 - 3.0.25rc3</td>
1349         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2447">CVE-2007-2447</a></td>
1350         <td><a href="/samba/security/CVE-2007-2447.html">Announcement</a></td>
1351     </tr>
1352
1353     <tr>
1354         <td>14 May 2007</td>
1355         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2446_v2.patch">patch for Samba 3.0.24</a></td>
1356         <td>Multiple Heap Overflows Allow Remote Code Execution (Updated May 25 to fix regression in Samba domain controller logon code).</td>
1357         <td>Samba 3.0.0 - 3.0.25rc3</td>
1358         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2446">CVE-2007-2446</a></td>
1359         <td><a href="/samba/security/CVE-2007-2446.html">Announcement</a></td>
1360     </tr>
1361
1362     <tr>
1363         <td>14 May 2007</td>
1364         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2444_v2.patch">patch for Samba 3.0.24</a></td>
1365         <td>Local SID/Name translation bug can result in user privilege elevation (Updated May 25 to fix regression in the &quot;force group&quot; parameter).</td>
1366         <td>Samba 3.0.23d - 3.0.25pre2</td>
1367         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2444">CVE-2007-2444</a></td>
1368         <td><a href="/samba/security/CVE-2007-2444.html">Announcement</a></td>
1369     </tr>
1370
1371     <tr>
1372         <td>5 Feb 2007</td>
1373         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0452.patch">patch for Samba 3.0.23d</a></td>
1374         <td>Potential Denial of Service bug in smbd</td>
1375         <td>Samba 3.0.6 - 3.0.23d</td>
1376         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452">CVE-2007-0452</a></td>
1377         <td><a href="/samba/security/CVE-2007-0452.html">Announcement</a></td>
1378     </tr>
1379
1380     <tr>
1381         <td>5 Feb 2007</td>
1382         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0453.patch">patch for Samba 3.0.23d</a></td>
1383         <td>Buffer overrun in NSS host lookup Winbind library on Solaris</td>
1384         <td>Samba 3.0.21 - 3.0.23d</td>
1385         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0453">CVE-2007-0453</a></td>
1386         <td><a href="/samba/security/CVE-2007-0453.html">Announcement</a></td>
1387     </tr>
1388
1389     <tr>
1390         <td>5 Feb 2007</td>
1391         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0454.patch">patch for Samba 3.0.23d</a></td>
1392         <td>Format string bug in afsacl.so VFS plugin</td>
1393         <td>Samba 3.0.6 - 3.0.23d</td>
1394         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0454">CVE-2007-0454</a></td>
1395         <td><a href="/samba/security/CVE-2007-0454.html">Announcement</a></td>
1396     </tr>
1397
1398     <tr>
1399         <td>10 July 2006</td>
1400         <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2006-3403.patch">patch for Samba 3.0.1 - 3.0.22</a></td>
1401         <td>Memory exhaustion DoS against smbd</td>
1402         <td>Samba 3.0.1 - 3.0.22</td>
1403         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3403">CVE-2006-3403</a></td>
1404         <td><a href="/samba/security/CVE-2006-3403.html">Announcement</a></td>
1405     </tr>
1406
1407     <tr>
1408     <tr>
1409         <td>30 March 2006</td>
1410         <td><a href="/samba/ftp/patches/security/samba-3.0.21-CVE-2006-1059.patch">patch for Samba 3.0.21[a-c]</a></td>
1411         <td>Exposure of machine account credentials in winbind log files</td>
1412         <td>Samba 3.0.21 - 3.0.21c</td>
1413         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1059">CVE-2006-1059</a></td>
1414         <td><a href="/samba/security/CVE-2006-1059.html">Announcement</a></td>
1415     </tr>
1416
1417     <tr>
1418         <td>16 December 2004</td>
1419         <td><a href="/samba/ftp/patches/security/samba-3.0.9-CVE-2004-1154.patch">patch for Samba 3.0.9</a></td>
1420         <td>Integer Overflow in security descriptor parsing</td>
1421         <td>Samba 2.x, 3.0.x &lt;&#61; 3.0.9</td>
1422         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154">CVE-2004-1154</a></td>
1423         <td><a href="/samba/security/CVE-2004-1154.html">Announcement</a></td>
1424     </tr>    
1425
1426     <tr>
1427     <tr>
1428         <td>15 November 2004</td>
1429         <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0882.patch">patch for &lt;&#61;Samba 3.0.7</a></td>
1430         <td>Buffer Overrun in smbd</td>
1431         <td>Samba 3.0.x &lt;&#61; 3.0.7</td>
1432         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0882">CVE-2004-0882</a></td>
1433         <td><a href="/samba/security/CVE-2004-0882.html">Announcement</a></td>
1434     </tr>    
1435
1436     <tr>
1437         <td>8 November 2004</td>
1438         <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0930.patch">patch for &lt;&#61;Samba 3.0.7</a></td>
1439         <td>Remote DoS</td>
1440         <td>Samba 3.0.x &lt;&#61; 3.0.7</td>
1441         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0930">CVE-2004-0930</a></td>
1442         <td><a href="/samba/security/CVE-2004-0930.html">Announcement</a></td>
1443     </tr>    
1444
1445     <tr>
1446         <td>30 September 2004</td>
1447         <td><a href="/samba/ftp/stable/samba-2.2.12.tar.gz">Samba 2.2.12</a> and/or  <a href="/samba/ftp/patches/security/samba-3.0.2a-reduce_name.patch">patch for &lt;&#61;Samba 3.0.2a</a></td>
1448         <td>Potential arbitrary file access</td>
1449         <td>Samba 2.2.x &lt;&#61;2.2.11 and Samba 3.0.x &lt;&#61;3.0.2a</td>
1450         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0815">CVE-2004-0815</a></td>
1451         <td><a href="/samba/security/CVE-2004-0815.html">Announcement</a></td>
1452     </tr>    
1453         
1454       
1455       <tr>
1456         <td>13 Sept 2004</td>
1457         <td><a href="/samba/ftp/patches/security/samba-3.0.5-DoS.patch">3.0.5 patch</a></td>
1458         <td>Two DoS bugs; one affecting smbd, the other nmbd.</td>
1459         <td>3.0.x &lt;= 3.0.6</td>
1460         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0807">CVE-2004-0807</a>, <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0808">CVE-2004-0808</a></td>
1461         <td><a href="/samba/security/CVE-2004-0807_CVE-2004-0808.html">Announcement</a></td>
1462       </tr>
1463       
1464       <tr>
1465         <td>22 Jul 2004</td>
1466         <td><a href="/samba/ftp/stable/samba-3.0.5.tar.gz">3.0.5</a></td>
1467         <td>Two potential buffer overruns</td>
1468         <td>>=3.0.2</td>
1469         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0600">CVE-2004-0600</a>, 
1470             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1471         </td>
1472         <td><a href="/samba/security/CVE-2004-0600.html">CVE-2004-0600 Announcement</a>
1473             <a href="/samba/security/CVE-2004-0686.html">CVE-2004-0686 Announcement</a></td>
1474       </tr>
1475       
1476       <tr>
1477         <td>22 Jul 2004</td>
1478         <td><a href="/samba/ftp/stable/samba-2.2.10.tar.gz">2.2.10</a></td>
1479         <td>Buffer overrun in hash mangling method</td>
1480         <td>all 2.2 releases</td>
1481         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1482         </td>
1483         <td><a href="/samba/history/samba-2.2.10.html">release notes</a></td>
1484       </tr>
1485       
1486       <tr>
1487         <td>9 Feb 2004</td>
1488         <td><a href="/samba/ftp/old-versions/samba-3.0.2a.tar.gz">3.0.2a</a></td>
1489         <td align="left">Password initialization bug that could grant
1490         an attacker unauthorized
1491         access to a user account created by the mksmbpasswd.sh shell script.</td>
1492         <td>>=3.0.0</td>
1493         <td><a
1494         href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0082">CVE-2004-0082</a></td>
1495         <td><a href="/samba/security/CVE-2004-0082.html">Announcement</a></td>
1496       </tr>
1497       
1498       <tr>
1499         <td>7 Apr 2003</td>
1500         <td><a href="/samba/ftp/old-versions/samba-2.2.8a.tar.gz">2.2.8a</a></td>
1501         <td>Buffer overrun condition in the SMB/CIFS packet fragment
1502         re-assembly code.</td>
1503         <td>all 2.0 releases and <= 2.2.8</td>
1504         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0196">CVE-2003-0196</a>,
1505         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201">CVE-2003-0201</a></td>
1506         <td><a href="/samba/history/samba-2.2.8a.html">release notes</a></td>
1507       </tr>
1508       
1509       <tr>
1510         <td>10 Dec 2002</td>
1511         <td><a href="/samba/ftp/old-versions/samba-2.2.7a.tar.gz">2.2.7a</a></td>
1512         <td>Bug in the length checking for encrypted password change
1513         requests from clients.</td>
1514         <td>2.2.2 - 2.2.6</td>
1515         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0085">CVE-2003-0085</a></td>
1516         <td><a href="/samba/history/samba-2.2.7a.html">release notes</a></td>
1517       </tr>
1518       
1519       <tr>
1520         <td>23 Jun 2001</td>
1521         <td><a href="/samba/ftp/old-versions/samba-2.2.0a.tar.gz">2.2.0a</a></td>
1522         <td>Bug in expansion of certain smb.conf variables such as 
1523         %m that could grant an attacker the capability to overwrite arbitrary 
1524         files on the server.  Bug that causes smbd not to honor the hosts allow 
1525         and deny smb.conf directives.</td>
1526         <td>2.2.0</td>
1527         <td>&nbsp</td>
1528         <td><a href="/samba/history/samba-2.2.0a.html">release notes</a></td>
1529       </tr>
1530       
1531       <tr>
1532         <td>23 Jun 2001</td>
1533         <td><a href="/samba/ftp/old-versions/samba-2.0.10.tar.gz">2.0.10</a></td>
1534         <td>Bug in the handling of temporary files that allows local 
1535         users to destroy data on local devices.</td>
1536         <td>>= 2.0.0</td>
1537         <td>&nbsp</td>
1538         <td><a href="/samba/history/samba-2.0.10.html">release notes</a></td>
1539       </tr>
1540                 
1541     </table>
1542     
1543     <p><em>If you suspect you have discovered a serious security hole in a
1544 Samba release, please send an email to <a
1545 href="mailto:security@samba.org">security@samba.org</a>.</em></p>
1546
1547 <!--#include virtual="footer_history.html" -->