Path to this page:
Subject: CVS commit: pkgsrc/net/samba
From: Takahiro Kambe
Date: 2014-03-17 15:01:57
Message id: 20140317140157.2EEF796@cvs.netbsd.org
Log Message:
Update samba to 3.6.23.
==============================
Release Notes for Samba 3.6.23
March 11, 2014
==============================
This is a security release in order to address
CVE-2013-4496 (Password lockout not enforced for SAMR password changes).
o CVE-2013-4496:
Samba versions 3.4.0 and above allow the administrator to implement
locking out Samba accounts after a number of bad password attempts.
However, all released versions of Samba did not implement this check for
password changes, such as are available over multiple SAMR and RAP
interfaces, allowing password guessing attacks.
Files: