Commit Graph

134 Commits

Author SHA1 Message Date
Arne Fitzenreiter
812faee44d samba: update rootfiles
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2021-09-11 08:46:48 +00:00
Adolf Belka
c4df0637a4 samba: Update version to 4.14.6
- Update from 4.14.4 to 4.14.6
- Update of rootfile not required
- Changelog
   Release Notes for Samba 4.14.6
        * BUG 14722: s3: lib: Fix talloc heirarcy error in parent_smb_fname().
        * BUG 14732: smbd: Fix pathref unlinking in create_file_unixpath().
        * BUG 14734: s3: VFS: default: Add proc_fd's fallback for vfswrap_fchown().
        * BUG 14736: s3: smbd: Remove erroneous TALLOC_FREE(smb_fname_parent) in
          change_file_owner_to_parent() error path.
        * BUG 14730: NT_STATUS_FILE_IS_A_DIRECTORY error messages when using
          glusterfs VFS module.
        * BUG 14734: s3/modules: fchmod: Fallback to path based chmod if pathref.
        * BUG 14740: Spotlight RPC service doesn't work with vfs_glusterfs.
        * BUG 14750: gensec_krb5: Restore ipv6 support for kpasswd.
        * BUG 14752: smbXsrv_{open,session,tcon}: protect
          smbXsrv_{open,session,tcon}_global_traverse_fn against invalid records.
        * BUG 14027: samba-tool domain backup offline doesn't work against bind DLZ
          backend.
        * BUG 14669: netcmd: Use next_free_rid() function to calculate a SID for
          restoring a backup.
   Release Notes for Samba 4.14.5
        * BUG 14696: s3: smbd: SMB1 SMBsplwr doesn't send a reply packet on success.
        * BUG 14708: s3: smbd: Ensure POSIX default ACL is mapped into returned
          Windows ACL for directory handles.
        * BUG 14721: s3: smbd: Fix uninitialized memory read in
          process_symlink_open() when used with vfs_shadow_copy2().
        * BUG 14689: docs: Expand the "log level" docs on audit logging.
        * BUG 14714: smbd: Correctly initialize close timestamp fields.
        * BUG 14699: Fix gcc11 compiler issues.
        * BUG 14718: docs-xml: Update smbcacls manpage.
        * BUG 14719: docs: Update list of available commands in rpcclient.
        * BUG 14475: ctdb: Fix a crash in run_proc_signal_handler().
        * BUG 14695: s3:winbind: For 'security = ADS' require realm/workgroup to be
          set.
        * BUG 14699: lib:replace: Do not build strndup test with gcc 11 or newer.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2021-07-19 18:22:35 +00:00
Michael Tremer
f1fc2193a7 Bump release of all packages with CGI files
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-06-18 15:08:57 +00:00
Adolf Belka
b33473414d samba: Update to 4.14.4
- Update from 4.14.3 to 4.14.4
- Update of rootfile not required
- Changelog
    Release Notes for Samba 4.14.4 April 29, 2021
     This is a security release in order to address the following defect:
      o CVE-2021-20254: Negative idmap cache entries can cause incorrect
        group entries in the Samba file server process token.
    Details
      o  CVE-2021-20254:
         The Samba smbd file server must map Windows group identities (SIDs) into unix
         group ids (gids). The code that performs this had a flaw that could allow it
         to read data beyond the end of the array in the case where a negative cache
         entry had been added to the mapping cache. This could cause the calling code
         to return those values into the process token that stores the group
         membership for a user.
         Most commonly this flaw caused the calling code to crash, but an alert user
         (Peter Eriksson, IT Department, Linköping University) found this flaw by
         noticing an unprivileged user was able to delete a file within a network
         share that they should have been disallowed access to.
         Analysis of the code paths has not allowed us to discover a way for a
         remote user to be able to trigger this flaw reproducibly or on demand,
         but this CVE has been issued out of an abundance of caution.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-05-06 09:54:35 +00:00
Adolf Belka
31daeebd00 samba: Update to 4.14.3
- Update from 4.13.7 to 4.14.3
   Change to Samba 4.14 release series
    4.13 is now in maintenance mode
    4.14 is now the current stable release series
- Update of x86_64 rootfile
- Checked library changes with find-dependencies
   No linked programs found
- Changelog
   o  Trever L. Adams <trever.adams@gmail.com>
      * BUG 14671: s3:modules:vfs_virusfilter: Recent New_VFS changes break
        vfs_virusfilter_openat.
   o  Andrew Bartlett <abartlet@samba.org>
      * BUG 14586: build: Notice if flex is missing at configure time.
   o  Ralph Boehme <slow@samba.org>
      * BUG 14672: Fix smbd panic when two clients open same file.
      * BUG 14675: Fix memory leak in the RPC server.
      * BUG 14679: s3: smbd: fix deferred renames.
   o  Samuel Cabrero <scabrero@samba.org>
      * BUG 14675: s3-iremotewinspool: Set the per-request memory context.
   o  Volker Lendecke <vl@samba.org>
      * BUG 14675: Fix memory leak in the RPC server.
   o  Stefan Metzmacher <metze@samba.org>
      * BUG 11899: third_party: Update socket_wrapper to version 1.3.2.
      * BUG 14640: third_party: Update socket_wrapper to version 1.3.3.
   o  David Mulder <dmulder@suse.com>
      * BUG 14665: samba-gpupdate: Test that sysvol paths download in
        case-insensitive way.
   o  Sachin Prabhu <sprabhu@redhat.com>
      * BUG 14662: smbd: Ensure errno is preserved across fsp destructor.
   o  Christof Schmitt <cs@samba.org>
      * BUG 14663: idmap_rfc2307 and idmap_nss return wrong mapping for uid/gid
        conflict.
   o  Martin Schwenke <martin@meltin.net>
      * BUG 14288: build: Only add -Wl,--as-needed when supported.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-04-26 10:06:43 +00:00
Adolf Belka
da3edeeecf samba: Update to 4.13.7
- Update from 4.13.4 to 4.13.7
- Update of x68_64 rootfile
- Changelog
   Release Notes for Samba 4.13.7 March 24, 2021
    This is a security release in order to address the following defects:
    o  CVE-2020-27840:
       An anonymous attacker can crash the Samba AD DC LDAP server by sending easily
       crafted DNs as part of a bind request. More serious heap corruption is likely
       also possible.
         Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
          * BUG 14595: CVE-2020-27840: Fix unauthenticated remote heap corruption via
            bad DNs.
    o  CVE-2021-20277:
       User-controlled LDAP filter strings against the AD DC LDAP server may crash
       the LDAP server.
         Andrew Bartlett <abartlet@samba.org>
          * BUG 14655: CVE-2021-20277: Fix out of bounds read in ldb_handler_fold.
         Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
          * BUG 14655: CVE-2021-20277: Fix out of bounds read in ldb_handler_fold.
   Release Notes for Samba 4.13.5 March 09, 2021
    This is the latest stable release of the Samba 4.13 release series.
    o  Trever L. Adams <trever.adams@gmail.com>
       * BUG 14634: s3:modules:vfs_virusfilter: Recent talloc changes cause infinite
         start-up failure.
    o  Jeremy Allison <jra@samba.org>
       * BUG 13992: s3: libsmb: Add missing cli_tdis() in error path if encryption
         setup failed on temp proxy connection.
       * BUG 14604: smbd: In conn_force_tdis_done() when forcing a connection closed
         force a full reload of services.
    o  Andrew Bartlett <abartlet@samba.org>
       * BUG 14593: dbcheck: Check Deleted Objects and reduce noise in reports about
         expired tombstones.
    o  Ralph Boehme <slow@samba.org
       * BUG 14503: s3: Fix fcntl waf configure check.
       * BUG 14602: s3/auth: Implement "winbind:ignore domains".
       * BUG 14617: smbd: Use fsp->conn->session_info for the initial
         delete-on-close token.
    o  Peter Eriksson <pen@lysator.liu.se>
       * BUG 14648: s3: VFS: nfs4_acls. Add missing TALLOC_FREE(frame) in error
         path.
    o  Björn Jacke <bj@sernet.de>
       * BUG 14624: classicupgrade: Treat old never expires value right.
    o  Volker Lendecke <vl@samba.org>
       * BUG 14636: g_lock: Fix uninitalized variable reads.
    o  Stefan Metzmacher <metze@samba.org>
       * BUG 13898: s3:pysmbd: Fix fd leak in py_smbd_create_file().
    o  Andreas Schneider <asn@samba.org>
       * BUG 14625: lib:util: Avoid free'ing our own pointer.
    o  Paul Wise <pabs3@bonedaddy.net>
       * BUG 12505: HEIMDAL: krb5_storage_free(NULL) should work.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-04-01 12:36:01 +00:00
Michael Tremer
e514d67f8e samba: Update to 4.13.4
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-02-03 22:50:36 +00:00
Michael Tremer
37fe3658a0 samba: Add helper script to pipe password
It is complicated to set the password in the C helper binary.

Therefore it is being set by a helper script.

This is still not an optimal solution since the password might be
exposed to the shell environment, but has the advantage that shell
command injection is no longer possible.

Fixes: #12562
Reported-by: Albert Schwarzkopf <ipfire@quitesimple.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2021-01-27 21:06:57 +00:00
Arne Fitzenreiter
31cbb589d9 samba: remove pid at killproc in initscript
sometime a stale nmbd or smbd process prevent start of samba.
this change should kill all processes.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2020-11-14 08:05:34 +00:00
Michael Tremer
1e2c442c9e samba: Add support for custom configuration changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-11-09 18:43:15 +00:00
Arne Fitzenreiter
632075bf57 samba: update to 4.13.1
This is a security release in order to address
CVE-2020-14318 (Missing handle permissions check in SMB1/2/3 ChangeNotify),
CVE-2020-14323 (Unprivileged user can crash winbind) and
CVE-2020-14383 (An authenticated user can crash the DCE/RPC DNS with easily
crafted records).

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-30 17:31:29 +00:00
Michael Tremer
74fd04c335 samba: Bump package release
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-27 11:44:34 +00:00
Michael Tremer
a5aba922a8 samba: Bump package version
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-13 17:07:07 +01:00
Michael Tremer
be1554336d samba: Export all printers from CUPS
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-13 17:06:16 +01:00
Michael Tremer
5aa5f6777a samba: Remove reset options
This only requires that we have to change multiple files with
the same settings.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-13 17:06:16 +01:00
Michael Tremer
13e455aec7 samba: Log to syslog
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-13 17:06:16 +01:00
Michael Tremer
391540d9d8 samba: Link against avahi
We should use avahi to announce file sharing services to
the network using mDNS, too.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-07 08:09:36 +00:00
Arne Fitzenreiter
1dd31d858e samba: update to 4.13.0
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2020-10-06 12:19:04 +00:00
Michael Tremer
2dc2a27803 lfs: Drop quotes in DEPS variable
Not sure why this has ever been there. This simply makes it
nicer to read and edit because we can have line-breaks now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2020-03-24 08:57:27 +00:00
Wolfgang Apolinarski
23164efba5 Parallelized build for several packages
Added $(MAKETUNING) to several packages.
Marked packages that do not support parallel build.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-03-04 11:02:03 +00:00
Peter Müller
eee037b890 update disclaimer in LFS files
Most of these files still used old dates and/or domain names for contact
mail addresses. This is now replaced by an up-to-date copyright line.

Just some housekeeping... :-)

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-09-10 19:20:36 +01:00
Michael Tremer
f7881486df samba: FTBFS on aarch64
Needed automake update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-05-31 12:03:47 +01:00
Arne Fitzenreiter
0476a6570d samba: import security updates from redhead
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-11-27 18:20:59 +01:00
Arne Fitzenreiter
369a04a49d samba: remove winbind tevent poll patch
this not work without matching libtevent

fixes #11390

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-06-10 17:08:05 +02:00
Arne Fitzenreiter
feadf6285e samba: bump package version
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-05-30 21:29:53 +02:00
Matthias Fischer
82d25bae62 samba 3.6.25: fixes for lfs-file
Removed 'unrecognized' configure-options.

Deleted empty tab at line end and moved line '-mkdir -p /var/ipfire/samba'
because of error message:
'mkdir: cannot create directory ‘/var/ipfire/samba’: File exists'

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-05-30 21:08:06 +02:00
Arne Fitzenreiter
1d13e6373a samba: add current RHEL6 patches
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2017-05-28 10:40:09 +02:00
Jonatan Schlag
e215aaed48 samba: move initscript to src/initscripts/packages and use new macro
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2017-02-24 15:54:19 +01:00
Jonatan Schlag
4141e0aad1 Update krb5 to 1.14.4
This commit updates krb5 to version 1.14.4
The patch is removed, because he is upstream since 1.12.2.
The samba version is incremented, to link samba against the new krb5
version. Otherwise samba for example is linked against
/usr/lib/libkdb5.so.7 but the current version is /usr/lib/libkdb5.so.8

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-09-26 14:42:08 +01:00
Arne Fitzenreiter
55c645ba48 samba: import updated rpc security patchset from red hat.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-05-23 23:08:01 +02:00
Arne Fitzenreiter
c0119cfb37 samba: import rpc server and client fixes.
should fix: #11110

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-04-28 17:04:58 +02:00
Arne Fitzenreiter
77ecb239d3 samba: import RHEL security fixes.
CVE-2015-7560
CVE-2016-2110
CVE-2016-2111
CVE-2016-2112
CVE-2016-2115
CVE-2016-2118 aka Badlock
CVE-2015-5370

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-04-13 22:25:14 +02:00
Arne Fitzenreiter
5bbf213dc7 samba: security update to 3.6.25.
Fix CVE-2015-0240 (unexpected code execution in smbd).
2015-02-23 16:51:15 +01:00
Arne Fitzenreiter
d70f58f60c samba: fix mode of winbindd_privileged folder. 2014-11-30 09:25:56 +01:00
Arne Fitzenreiter
d2ff1cc455 samba: bump PAK_VER. 2014-08-22 17:03:19 +02:00
Michael Tremer
2deb75c0f3 Merge remote-tracking branch 'ms/squid-ad' into next 2014-07-27 12:01:50 +02:00
Arne Fitzenreiter
ef7686badb samba: fix version. 2014-06-24 06:48:41 +02:00
Arne Fitzenreiter
4c1e9ae0d9 samba: security update to 3.6.24.
This is a security releases in order to address
CVE-2014-0244 (Denial of service - CPU loop) and
CVE-2014-3493 (Denial of service - Server crash/memory corruption).
2014-06-23 23:04:27 +02:00
Michael Tremer
889219356e samba: Make sure that permissions of the lock dir are fine. 2014-06-12 16:14:11 +02:00
Michael Tremer
603248db53 squid: Add NTLM authentication against Windows Active Directory servers. 2014-06-10 20:15:58 +02:00
Michael Tremer
879dafbf17 samba: Enable support for AD. 2014-06-10 20:13:23 +02:00
Arne Fitzenreiter
38cacce21b samba: update to 3.6.23. 2014-03-13 12:45:56 +01:00
Arne Fitzenreiter
af2dcb40f6 samba: update to 3.6.22.
Samba 3.6.22 have been issued as security releases in order
to address CVE-2013-4408 (DCE-RPC fragment length field is incorrectly checked)
and CVE-2012-6150 (pam_winbind login without require_membership_of
restrictions).
2013-12-10 00:07:36 +01:00
Arne Fitzenreiter
352495313d samba: update to 3.6.21. 2013-11-30 12:38:16 +01:00
Arne Fitzenreiter
d48c456fa2 samba: update to 3.6.20.
These are security releases in order to address CVE-2013-4475
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475
(ACLs are not checked on opening an alternate data stream on
a file or directory) and CVE-2013-4476
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4476
(Private key in key.pem world readable).
2013-11-13 13:56:40 +01:00
Arne Fitzenreiter
9fa2cb9c49 samba: update to 3.6.18. 2013-08-14 19:13:33 +02:00
Arne Fitzenreiter
726a85b8c1 samba: update to 3.6.17. 2013-08-06 15:01:26 +02:00
Arne Fitzenreiter
4d638d5ec9 samba: update to 3.6.16. 2013-06-20 15:24:17 +02:00
Arne Fitzenreiter
a9a58c609a samba: updated to 3.6.15. 2013-05-08 16:11:20 +02:00
Arne Fitzenreiter
96b397c471 samba: updated to 3.6.14. 2013-05-06 16:04:31 +02:00