-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 12 Apr 2016 16:18:57 +1200 Source: samba Binary: samba samba-libs samba-common samba-common-bin smbclient samba-testsuite registry-tools libparse-pidl-perl samba-dev samba-doc python-samba samba-dsdb-modules samba-vfs-modules libpam-smbpass libsmbclient libsmbclient-dev winbind libpam-winbind libnss-winbind samba-dbg libwbclient0 libwbclient-dev ctdb Architecture: amd64 Version: 2:4.2.10+dfsg-0+deb8u1 Distribution: jessie-security Urgency: high Maintainer: amd64 Build Daemon (binet) Changed-By: Andrew Bartlett Description: ctdb - clustered database to store temporary data libnss-winbind - Samba nameservice integration plugins libpam-smbpass - pluggable authentication module for Samba libpam-winbind - Windows domain authentication integration plugin libparse-pidl-perl - IDL compiler written in Perl libsmbclient - shared library for communication with SMB/CIFS servers libsmbclient-dev - development files for libsmbclient libwbclient-dev - Samba winbind client library - development files libwbclient0 - Samba winbind client library python-samba - Python bindings for Samba registry-tools - tools for viewing and manipulating the Windows registry samba - SMB/CIFS file, print, and login server for Unix samba-common - common files used by both the Samba server and client samba-common-bin - Samba common files used by both the server and the client samba-dbg - Samba debugging symbols samba-dev - tools for extending Samba samba-doc - Samba documentation samba-dsdb-modules - Samba Directory Services Database samba-libs - Samba core libraries samba-testsuite - test suite from Samba samba-vfs-modules - Samba Virtual FileSystem plugins smbclient - command-line SMB/CIFS clients for Unix winbind - service to resolve user and group information from Windows NT ser Closes: 813406 Changes: samba (2:4.2.10+dfsg-0+deb8u1) jessie-security; urgency=high . [ Jelmer Vernooij ] * New upstream release. + Drop patch Fix-CTDB-build-with-PMDA.patch: applied upstream. * Re-enable cluster support. * Add patch no_wrapper: avoid dependencies on {nss,uid,socket}_wrapper. . [ Mathieu Parent ] * Fix CTDB behavior since CVE-2015-8543 (Closes: #813406) * Don't build ctdb twice: - Shorten build time - Fix ctdb log path from /var/log/log.ctdb to /var/log/ctdb/log.ctdb - Remove unused /usr/lib/*/ctdb/*.so files . [ Andrew Bartlett ] * New upstream release + Fixes: - CVE-2015-5370 (Multiple errors in DCE-RPC code) - CVE-2016-2110 (Man in the middle attacks possible with NTLMSSP) - CVE-2016-2111 (NETLOGON Spoofing Vulnerability) - CVE-2016-2112 (LDAP client and server don't enforce integrity) - CVE-2016-2113 (Missing TLS certificate validation) - CVE-2016-2114 ("server signing = mandatory" not enforced) - CVE-2016-2115 (SMB IPC traffic is not integrity protected) - CVE-2016-2118 (SAMR and LSA man in the middle attacks possible) * Backport BackupKey patches from Samba 4.3.0 to avoid regressions * Additional regression fix for 'net ads join' to a Windows 2003 domain by metze * Revert the change to made libsamba-debug a library, allowing openchange to link to Samba 4.2 * Add Breaks against openchangeproxy that uses an API and ABI that has changed . [ Marc Deslauriers ] * Fix double-free in pam_smbpass Checksums-Sha1: f5cd09ff2044de3de68db3432a78286f9ddb0cd5 1873722 samba_4.2.10+dfsg-0+deb8u1_amd64.deb 87e1920b89f5303c4c1cc54dc5d379d0b3726150 4240038 samba-libs_4.2.10+dfsg-0+deb8u1_amd64.deb 21e0c83c1dadd495a339677b01af2ac22570ba6d 612500 samba-common-bin_4.2.10+dfsg-0+deb8u1_amd64.deb bdf5b905cb45e6c6ae32fc453b294d567210f5a6 335362 smbclient_4.2.10+dfsg-0+deb8u1_amd64.deb 00f522cdad45a2a9ef1bf801ddc475e9e12865af 1568886 samba-testsuite_4.2.10+dfsg-0+deb8u1_amd64.deb 027c6dd54e5d103696e917ae8efa1f6d38ada91f 120806 registry-tools_4.2.10+dfsg-0+deb8u1_amd64.deb 9d5327b7176b60c7fc0f1fa202163fb6a8a71d88 182008 libparse-pidl-perl_4.2.10+dfsg-0+deb8u1_amd64.deb 13b96c36658eb22eb39bf49d9eb9fb3cfd80f515 332810 samba-dev_4.2.10+dfsg-0+deb8u1_amd64.deb 5b792a4dd3f8e8ae336ad0c42031d401a7c3a5e5 1012136 python-samba_4.2.10+dfsg-0+deb8u1_amd64.deb 51e79f6abdb037442b324720ba6b90347bbafdb1 304632 samba-dsdb-modules_4.2.10+dfsg-0+deb8u1_amd64.deb 2a98249e6b013304eb731fcc7c3f8783e524a2c1 326446 samba-vfs-modules_4.2.10+dfsg-0+deb8u1_amd64.deb b714439841d09e31388695291ee850eccf03375e 108854 libpam-smbpass_4.2.10+dfsg-0+deb8u1_amd64.deb 132d8a7e0f5860e4c86d83d70f9cbf57e605c83f 144848 libsmbclient_4.2.10+dfsg-0+deb8u1_amd64.deb 1e4f3f77d5e99b60545a8be90f19141344327731 131530 libsmbclient-dev_4.2.10+dfsg-0+deb8u1_amd64.deb 2c6c2e24411021703ffd112a5cd562703d2a8b93 492330 winbind_4.2.10+dfsg-0+deb8u1_amd64.deb 17903e1133f42eff88aa4b6ef75e26a25c05ee46 120076 libpam-winbind_4.2.10+dfsg-0+deb8u1_amd64.deb d5491c5c76b374e2ecad8d7d7fd30c714fe33fa8 104588 libnss-winbind_4.2.10+dfsg-0+deb8u1_amd64.deb 349763f8cc5963bd67ed8503e39d4d69755e68cc 29492526 samba-dbg_4.2.10+dfsg-0+deb8u1_amd64.deb 3015b9c7a29df915c488ec712113a5576a3dfa66 119056 libwbclient0_4.2.10+dfsg-0+deb8u1_amd64.deb 9c86410394fd9f883c1b64492d364f955d3cdd6f 104208 libwbclient-dev_4.2.10+dfsg-0+deb8u1_amd64.deb 635b932986cadf173c69bf5855a4b2d585e184d1 508810 ctdb_4.2.10+dfsg-0+deb8u1_amd64.deb Checksums-Sha256: 6436809deb1684d518a2c46fd8dc2a562810c7d239d437d332dc848bccbaef54 1873722 samba_4.2.10+dfsg-0+deb8u1_amd64.deb ec246f24defe54a2f2c69e460ff0086c0fa4a27d041749b3cfbcce98617ad759 4240038 samba-libs_4.2.10+dfsg-0+deb8u1_amd64.deb 7606b395f5f8e86d890939fce172904153acf136d6bfa75d418c5d5266ebb41c 612500 samba-common-bin_4.2.10+dfsg-0+deb8u1_amd64.deb 0775733ced7474df559372ba63114a784a65ad6243d075dac8c5ed24c97c31ec 335362 smbclient_4.2.10+dfsg-0+deb8u1_amd64.deb 307e77a3e8b7b8f5a9223464712a6792d593b4d5ea42649bec4df0dd40939275 1568886 samba-testsuite_4.2.10+dfsg-0+deb8u1_amd64.deb ebb0c72213ad42fb6af507297f9830e825406141141967b3da43c8731c2166cb 120806 registry-tools_4.2.10+dfsg-0+deb8u1_amd64.deb 9f68d733683df17de41977b20f53e9f63aed722573290ad91b7a49e9b86d9754 182008 libparse-pidl-perl_4.2.10+dfsg-0+deb8u1_amd64.deb 6af2f620b3fab6372da1bf95865562be99d7d4ef806638b949dd1054ee4c00b1 332810 samba-dev_4.2.10+dfsg-0+deb8u1_amd64.deb 90358783909b190bddbadb732b7749769598ce002c611573bd6a9b387ed68cf0 1012136 python-samba_4.2.10+dfsg-0+deb8u1_amd64.deb ebec3755892c6eea855fdfac501922979b5209b5373d75e747d86da1f5257968 304632 samba-dsdb-modules_4.2.10+dfsg-0+deb8u1_amd64.deb 08558c2bf28465828dcc51dcbd7dd6d8f4cf45b70dc607bb802eb508fa29270d 326446 samba-vfs-modules_4.2.10+dfsg-0+deb8u1_amd64.deb 7cfac9544eaa74a87e6f31b509cf1432f5ff8499aabf5ad9c50acbb005153ce5 108854 libpam-smbpass_4.2.10+dfsg-0+deb8u1_amd64.deb 6362e8364861af8cd6442ba41159947c0ab823475141f739e48c78e0bad376c5 144848 libsmbclient_4.2.10+dfsg-0+deb8u1_amd64.deb 2c6c4b2acffeb607aa6f933373dfaaa32593b30d6a565051f60344ea246e5310 131530 libsmbclient-dev_4.2.10+dfsg-0+deb8u1_amd64.deb da470611e98c2fd802080f646301e454ab3f6469b5c8f7675636f9280a75ac2b 492330 winbind_4.2.10+dfsg-0+deb8u1_amd64.deb 37cb66d481fa8be1e225a6c42ae0c5872888fb20f2cd06a1bafc0a22412689fb 120076 libpam-winbind_4.2.10+dfsg-0+deb8u1_amd64.deb 411f86eb1d7026c43c51c13823164aa5c879bf7b123fb134e69405ac78b0d225 104588 libnss-winbind_4.2.10+dfsg-0+deb8u1_amd64.deb b108fa06495bd069a774f280a4bbfa2b6105e180a7322961e1176d83d5a46f50 29492526 samba-dbg_4.2.10+dfsg-0+deb8u1_amd64.deb 857e4d007137a16ee5b51818829fedf6cabf826bb10d2896e1a35ba3e940d007 119056 libwbclient0_4.2.10+dfsg-0+deb8u1_amd64.deb 17abdcf376d71b793d6af908b43fcf08eccbfd2cf64701a30d86d94c1cbe791a 104208 libwbclient-dev_4.2.10+dfsg-0+deb8u1_amd64.deb 1a278daf0d48972ff267f02ff91754dc902d2803b6eba30b2545d1052c5fc796 508810 ctdb_4.2.10+dfsg-0+deb8u1_amd64.deb Files: 13af3174dd7cf50ddb3dc869526bfd08 1873722 net optional samba_4.2.10+dfsg-0+deb8u1_amd64.deb 785a1c6cd2fb01c311bb33e6266d7bd5 4240038 libs optional samba-libs_4.2.10+dfsg-0+deb8u1_amd64.deb 16fb7ffde203b8bcde7fd27c645e61d9 612500 net optional samba-common-bin_4.2.10+dfsg-0+deb8u1_amd64.deb 520da0ed8dd6b39f8a9c1ea1c11d1c5a 335362 net optional smbclient_4.2.10+dfsg-0+deb8u1_amd64.deb a088b8707caef86755abb4df6a98266a 1568886 net optional samba-testsuite_4.2.10+dfsg-0+deb8u1_amd64.deb f5e9fe69d72124149baed0de91a2f4c0 120806 net optional registry-tools_4.2.10+dfsg-0+deb8u1_amd64.deb f2f7fc3472aeb93b370162c76f61026e 182008 perl optional libparse-pidl-perl_4.2.10+dfsg-0+deb8u1_amd64.deb e2e44547ad7a7c924d3c72102e550503 332810 devel optional samba-dev_4.2.10+dfsg-0+deb8u1_amd64.deb 551c6ce2fedc3f7d8d21970aad0dd14e 1012136 python optional python-samba_4.2.10+dfsg-0+deb8u1_amd64.deb f7251b447f6beb411078b2e9e8823792 304632 libs optional samba-dsdb-modules_4.2.10+dfsg-0+deb8u1_amd64.deb 3d3bd2b44f2d01f3ecf61d41d3da3982 326446 net optional samba-vfs-modules_4.2.10+dfsg-0+deb8u1_amd64.deb 5d3531d01fc0200133280354d2d96f56 108854 admin extra libpam-smbpass_4.2.10+dfsg-0+deb8u1_amd64.deb 0ab38854426bc6749c1da8070292471b 144848 libs optional libsmbclient_4.2.10+dfsg-0+deb8u1_amd64.deb 28de5780829b72c2e36f1fe5f0fcdaff 131530 libdevel extra libsmbclient-dev_4.2.10+dfsg-0+deb8u1_amd64.deb e25d40a7ff45000783a3eb40deb7bde0 492330 net optional winbind_4.2.10+dfsg-0+deb8u1_amd64.deb 13fd074a8cfabf5db7943ffe4b3469b7 120076 net optional libpam-winbind_4.2.10+dfsg-0+deb8u1_amd64.deb 9a77f11892572c5eb3a9955e2b1a9b83 104588 net optional libnss-winbind_4.2.10+dfsg-0+deb8u1_amd64.deb 58387841177f46d1122615d2c007f786 29492526 debug extra samba-dbg_4.2.10+dfsg-0+deb8u1_amd64.deb ae55407812eb09af3948b7d1bd753e52 119056 libs optional libwbclient0_4.2.10+dfsg-0+deb8u1_amd64.deb 649bd2aeb81a813da35ed92da4e4976e 104208 libdevel optional libwbclient-dev_4.2.10+dfsg-0+deb8u1_amd64.deb 7aa18a9db9fbc5413bfb58479dc38966 508810 net optional ctdb_4.2.10+dfsg-0+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXDSKLAAoJEHwm3WW5odWghpsP/RpPhiIhJnmrXtJ7vKBhnnOp jYTVzU+14I6h6WFvaGZapxWupvuQzdWKkuS/SPjgMP5yTyTsGZRSWDMrblbB5Qa6 zsIp1ymWXj9kuJqQNIJgXilAfQvRZArZZYwgHuGmM5qQ5XpGXXsQHzy8AirD7d21 IN22UTZvWLzZdow+AHevhjO357hGgWYdPTqlRV4T8IPpwtICyk38ns2dMV2Q1IUX Qwf+MW0hsgNKquXXxFq5CNDMSqjzFiwtNoIYbyOJEk0DPuoukLvbuhSGr5zK6HVN BkSn87pSsrFaQRQ+kGOxomzVwOzLX1+JIfs6cFkhKdd8RQXJTvRqO4x3H7Gzrw9f mX15grnsnHKetS2Iyf2KNjnPlDw2RTEMwN/h8UE6gHdj6xMAvmF+60dIpr6lMClN 0sPwBQxnAd7sS56Px+QRJG3anwx/w3iZOYLRRAiyLGqNN3wUPG2wV/a+DUedsScB bmHMjeSrNj104jF5VSGaNXVhk3GaQ9Bowgd5IBPAyGJLB7LCeVdu3gc5zlqDmWwk 6ctHcQ7DNxsjTipqKrUAGyIv571iSTZjII4XccSGU61XXWAmeQjN/Ms+khHMfszt GoP+zKMLjRkGCQPsfyVWKonhACxDj+rIaaVceNm0rFRtuY40/NzwxNm4EcLAR7rr PgD7O7kWxcjtTvamVwwq =XKY0 -----END PGP SIGNATURE-----