[Pkg-samba-maint] Bug#1004693: vfs_fruit module is in the binary package samba-vfs-modules

Eric Blackwell eblackwell at egnyte.com
Wed Feb 2 23:50:53 GMT 2022


Sorry for all of the noise. I did a bit more digging.
It seems that yes, this is in the vfs_fruit module, and yes that is in the
samba-vfs-modules package.
However, samba-vfs-modules is not a dependency of samba, it is a
recommended package:
https://salsa.debian.org/samba-team/samba/-/blob/master/debian/control#L92

Which means, for most people, most of the time, samba-vfs-modules will get
installed by default. So this likely affects a large majority of samba
users in Debian.

On Tue, 1 Feb 2022 21:51:11 -0800 Eric Blackwell <eblackwell at egnyte.com>
wrote:
> Ignore my previous reply. vfs_fruit is part of the samba-vfs-modules
> package in debian.
>
> On Tue, 1 Feb 2022 21:38:22 -0800 Eric Blackwell <eblackwell at egnyte.com>
> wrote:
> > It is actually a vulnerability in the vfs_fruit module which is included
> as
> > a standard module in the core samba package. So, it will likely affect
> > users with samba installed, and should be patched if possible.
> >
> > On Tue, 1 Feb 2022 10:02:48 +0000 Jonathan Dowland <jmtd at debian.org>
> wrote:
> > >  From what I can determine, the affected module is distributed in the
> > > samba-vfs-modules package, so any worried users trying to figure out
> > > whether they are vulnerable or not, check whether this package is
> > > installed: if not, you likely aren't.
> > >
> > >
> > > --
> > > Please do not CC me for listmail.
> > >
> > > 👱🏻 Jonathan Dowland
> > > ✎ jmtd at debian.org
> > > 🔗 https://jmtd.net
> > >
> > >
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-samba-maint/attachments/20220202/7f4490fa/attachment.htm>


More information about the Pkg-samba-maint mailing list