Path to this page:
Subject: CVS commit: pkgsrc/net/samba4
From: Thomas Klausner
Date: 2022-11-25 11:21:14
Message id: 20221125102114.56F34FA90@cvs.NetBSD.org
Log Message:
samba: update to 4.17.3.
This is a security release in order to address the following defects:
o CVE-2022-42898: Samba's Kerberos libraries and AD DC failed to guard against
integer overflows when parsing a PAC on a 32-bit system, which
allowed an attacker with a forged PAC to corrupt the heap.
https://www.samba.org/samba/security/CVE-2022-42898.html
Changes since 4.17.2
--------------------
o Joseph Sutton <josephsutton@catalyst.net.nz>
* BUG 15203: CVE-2022-42898
o Nicolas Williams <nico@twosigma.com>
* BUG 15203: CVE-2022-42898
Files: