Path to this page:
Subject: CVS commit: pkgsrc/net/samba4
From: Adam Ciarcinski
Date: 2019-06-19 23:22:59
Message id: 20190619212259.EA616FBF4@cvs.NetBSD.org
Log Message:
samba4: updated to 4.10.5
Release Notes for Samba 4.10.5
This is a security release in order to address the following defects:
o CVE-2019-12435 (Samba AD DC Denial of Service in DNS management server
(dnsserver))
o CVE-2019-12436 (Samba AD DC LDAP server crash (paged searches))
Details
=======
o CVE-2019-12435:
An authenticated user can crash the Samba AD DC's RPC server process via a
NULL pointer dereference.
o CVE-2019-12436:
An user with read access to the directory can cause a NULL pointer
dereference using the paged search control.
For more details and workarounds, please refer to the security advisories.
Files: