[Pkg-samba-maint] DO NOT REPLY [Bug 6853] mount.cifs race that allows user to replace mountpoint with a symlink

samba-bugs at samba.org samba-bugs at samba.org
Wed Feb 24 13:28:22 UTC 2010


https://bugzilla.samba.org/show_bug.cgi?id=6853





------- Comment #22 from jlayton at samba.org  2010-02-24 07:28 CST -------
(In reply to comment #21)
> Samba 3.5.0 is scheduled for monday.
> Is there a chance to get review flags asap?
> 

I added a review request for JRA (Jeremy, feel free to delegate to someone else
as long as they can get it done quickly)

> I am afraid that's too late for 3.4.6 (today) and I am struggling with myself
> whether to pick it for 3.3.11 or not. 3.3.11 is scheduled for friday so it's
> late, but hopefully it will be the last 3.3 maintenance release...
> 

A pity on 3.4.6, but let's go ahead and get those patches into v3-4-test so
that they make the next set of releases. I'd like to see it go into 3.3.11 too,
but I'll let you make that call if you think it's too risky.

I think what we want to do here is to treat this like a security issue in some
sense, and make sure that it gets into the next set of releases on all branches
(even as far back as v3.0). Because we have never installed mount.cifs as a
setuid program however, we don't need to do a special set of releases
specifically for this set of problems.


-- 
Configure bugmail: https://bugzilla.samba.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.



More information about the Pkg-samba-maint mailing list