diff options
author | Jule Anger <janger@samba.org> | 2023-03-22 10:13:09 +0100 |
---|---|---|
committer | Jule Anger <janger@samba.org> | 2023-03-29 15:22:38 +0200 |
commit | 68bdc867b873bce8187aeb3990b95c08a507abda (patch) | |
tree | 08fdae54c3d941ed950937bfc2837ce6e4b273c2 | |
parent | 04e5a7eb03a1e913f34d77b7b6c2353b41ef546a (diff) | |
download | samba-68bdc867b873bce8187aeb3990b95c08a507abda.tar.gz |
WHATSNEW: Add release notes for Samba 4.17.7.
Signed-off-by: Jule Anger <janger@samba.org>
-rw-r--r-- | WHATSNEW.txt | 74 |
1 files changed, 72 insertions, 2 deletions
diff --git a/WHATSNEW.txt b/WHATSNEW.txt index 865697ce109..694e29c45eb 100644 --- a/WHATSNEW.txt +++ b/WHATSNEW.txt @@ -1,4 +1,75 @@ ============================== + Release Notes for Samba 4.17.7 + March 29, 2023 + ============================== + + +This is a security release in order to address the following defects: + +o CVE-2023-0225: An incomplete access check on dnsHostName allows authenticated + but otherwise unprivileged users to delete this attribute from + any object in the directory. + https://www.samba.org/samba/security/CVE-2023-0225.html + +o CVE-2023-0922: The Samba AD DC administration tool, when operating against a + remote LDAP server, will by default send new or reset + passwords over a signed-only connection. + https://www.samba.org/samba/security/CVE-2023-0922.html + +o CVE-2023-0614: The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 + Confidential attribute disclosure via LDAP filters was + insufficient and an attacker may be able to obtain + confidential BitLocker recovery keys from a Samba AD DC. + Installations with such secrets in their Samba AD should + assume they have been obtained and need replacing. + https://www.samba.org/samba/security/CVE-2023-0614.html + + +Changes since 4.17.6 +-------------------- + +o Douglas Bagnall <douglas.bagnall@catalyst.net.nz> + * BUG 15276: CVE-2023-0225. + +o Andrew Bartlett <abartlet@samba.org> + * BUG 15270: CVE-2023-0614. + * BUG 15331: ldb wildcard matching makes excessive allocations. + * BUG 15332: large_ldap test is inefficient. + +o Rob van der Linde <rob@catalyst.net.nz> + * BUG 15315: CVE-2023-0922. + +o Joseph Sutton <josephsutton@catalyst.net.nz> + * BUG 14810: CVE-2020-25720 [SECURITY] Create Child permission should not + allow full write to all attributes (additional changes). + * BUG 15270: CVE-2023-0614. + * BUG 15276: CVE-2023-0225. + + +####################################### +Reporting bugs & Development Discussion +####################################### + +Please discuss this release on the samba-technical mailing list or by +joining the #samba-technical:matrix.org matrix room, or +#samba-technical IRC channel on irc.libera.chat. + +If you do report problems then please try to send high quality +feedback. If you don't provide vital information to help us track down +the problem then you will probably be ignored. All bug reports should +be filed under the Samba 4.1 and newer product in the project's Bugzilla +database (https://bugzilla.samba.org/). + + +====================================================================== +== Our Code, Our Bugs, Our Responsibility. +== The Samba Team +====================================================================== + + +Release notes for older releases follow: +---------------------------------------- + ============================== Release Notes for Samba 4.17.6 March 09, 2023 ============================== @@ -58,8 +129,7 @@ database (https://bugzilla.samba.org/). ====================================================================== -Release notes for older releases follow: ----------------------------------------- +---------------------------------------------------------------------- ============================== Release Notes for Samba 4.17.5 January 26, 2023 |