[Pkg-samba-maint] Situation of current samba security issues

Nico Golde nico at ngolde.de
Wed Oct 7 14:00:12 UTC 2009


Hi,
* Nico Golde <nico at ngolde.de> [2009-10-06 16:20]:
> * Christian Perrier <bubulle at debian.org> [2009-10-06 12:30]:
> [...] 
> > Stable
> > ------
> > Here lies the main problem.
> > 
> > Patches provided by upstream do *not* apply cleanly. They were created
> > against samba 3.2.14 while we have 3.2.5 in lenny.
> > 
> > The problem lies in samba-3.2.14-CVE-2009-2948-2.patch
> > 
> > Its last chunk deal with a part of code in source/client/mount.cifs.c
> > that was modified between 3.2.5 and 3.2.14. I have been unable to find
> > a solution to this and I'll be very very likely missing the needed
> > skills to do The Right Thing.
> > 
> > Steve Langasek being busy doing Ubuntu stuff hasn't got time to look
> > into this and we're at this very moment left in the dark...and I don't
> > like this..:-)
> 
> I will try to port it. Probably can't make it today but I'll 
> do it tomorrow.

http://people.debian.org/~nion/samba-3.2.14-CVE-2009-2948-2.patch

I did a few test and it seems to work as expected but please test as well :)

Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - nion at jabber.ccc.de - GPG: 0xA0A0AAAA
For security reasons, all text in this mail is double-rot13 encrypted.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 197 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-samba-maint/attachments/20091007/645ae5f4/attachment.pgp>


More information about the Pkg-samba-maint mailing list