-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 11 May 2023 10:52:40 +0300 Source: samba Architecture: source Version: 2:4.17.8+dfsg-1 Distribution: unstable Urgency: medium Maintainer: Debian Samba Maintainers <pkg-samba-maint@lists.alioth.debian.org> Changed-By: Michael Tokarev <mjt@tls.msk.ru> Changes: samba (2:4.17.8+dfsg-1) unstable; urgency=medium . * upstream stable/security/bugfix release, fixing the following issues: * https://bugzilla.samba.org/show_bug.cgi?id=14810 CVE-2020-25720 Create Child permission should not allow full write to all attributes (additional changes) * https://bugzilla.samba.org/show_bug.cgi?id=15143 New filename parser doesn't check veto files smb.conf parameter * https://bugzilla.samba.org/show_bug.cgi?id=15302 log flood: smbd_calculate_access_mask_fsp: Access denied: message level should be lower (this was included in Debian package already) * https://bugzilla.samba.org/show_bug.cgi?id=15306 Floating point exception (FPE) via cli_pull_send at source3/libsmb/clireadwrite.c * https://bugzilla.samba.org/show_bug.cgi?id=15313 Large directory optimization broken for non-lcomp path elements * https://bugzilla.samba.org/show_bug.cgi?id=15317 winbindd idmap child contacts the domain controller without a need * https://bugzilla.samba.org/show_bug.cgi?id=15318 idmap_autorid may fail to map sids of trusted domains for the * https://bugzilla.samba.org/show_bug.cgi?id=15319 idmap_hash doesn't use ID_TYPE_BOTH for reverse mappings * https://bugzilla.samba.org/show_bug.cgi?id=15323 net ads search -P doesn't work against servers in other domains * https://bugzilla.samba.org/show_bug.cgi?id=15325 dsgetdcname: assumes local system uses IPv4 * https://bugzilla.samba.org/show_bug.cgi?id=15328 test_tstream_more_tcp_user_timeout_spin fails intermittently on Rackspace GitLab runners * https://bugzilla.samba.org/show_bug.cgi?id=15329 Reduce flapping of ridalloc test * https://bugzilla.samba.org/show_bug.cgi?id=15329 Reduce flapping of ridalloc test * https://bugzilla.samba.org/show_bug.cgi?id=15338 DS ACEs might be inherited to unrelated object classes * https://bugzilla.samba.org/show_bug.cgi?id=15351 large_ldap test is unreliable * https://bugzilla.samba.org/show_bug.cgi?id=15353 Temporary smbXsrv_tcon_global.tdb can't be parsed * https://bugzilla.samba.org/show_bug.cgi?id=15354 mdssvc may crash when initializing * https://bugzilla.samba.org/show_bug.cgi?id=15357 streams_depot fails to create streams * https://bugzilla.samba.org/show_bug.cgi?id=15358 shadow_copy2 and streams_depot don't play well together * https://bugzilla.samba.org/show_bug.cgi?id=15360 Setting veto files = /.*/ break listing directories * https://bugzilla.samba.org/show_bug.cgi?id=15366 wbinfo -u fails on ad dc with >1000 users * d/gbp.conf: switch debian-branch to "bookworm" Checksums-Sha1: 753d7ea6aad0aeee7fd9e0db36905e2f689c5dcc 4398 samba_4.17.8+dfsg-1.dsc 9f440b3cf834725d0b60c1c91e0fb4b556983d2b 18437584 samba_4.17.8+dfsg.orig.tar.xz e3d89a496a760ea5afe0c4afbd6e49f908b786a7 269696 samba_4.17.8+dfsg-1.debian.tar.xz e1db58dd40d43bbce9ca927f75470371b8b7a316 6385 samba_4.17.8+dfsg-1_source.buildinfo Checksums-Sha256: 110586b57914391ba6cf4d9cf6a178f357e0fc52a6135e502ed1c8cdc2dd5732 4398 samba_4.17.8+dfsg-1.dsc b833118e6639e478b647102cb57c0047fbd504b48ab1d69f40536f6385a5980c 18437584 samba_4.17.8+dfsg.orig.tar.xz 7dd1a25fb490acbcdb549647cae11b80bf0cd248740b92a1c491ec2b5f42c1b9 269696 samba_4.17.8+dfsg-1.debian.tar.xz 562cba60d5d8d955605e8d2268f3aa9814ea5f1d6982d3eb8e6dc4c023cc85f6 6385 samba_4.17.8+dfsg-1_source.buildinfo Files: f57889a34844a2a814624a658bf12e90 4398 net optional samba_4.17.8+dfsg-1.dsc 8d4a82deb751bd216e63ad7f03abb4c5 18437584 net optional samba_4.17.8+dfsg.orig.tar.xz a67d6049f95ed86f6326b816731adb65 269696 net optional samba_4.17.8+dfsg-1.debian.tar.xz b827238b1a3ed11ce05b3941e1fd548a 6385 net optional samba_4.17.8+dfsg-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQFDBAEBCgAtFiEEe3O61ovnosKJMUsicBtPaxppPlkFAmRcoaAPHG1qdEB0bHMu bXNrLnJ1AAoJEHAbT2saaT5ZTsYIAK8nkljtkKW69Rur7501t9KQ5EtI5YyNsnjQ McB5MzZsKWLRvN+Kb9I4duUGNp1ZHH5Juy3y0yRbIP6ZYklZmfDGdMxvnEB1XPh/ vk+DCIVACiFVNsyAV0CikQGnLnJy0iChZzUo0IFqTKfUCOyxio/OWAYVIzFrgSGI 83tT/x75eeC37ZV59WLnDTM1yClbEtX4te/HN7t/5Lrreyzu+Eeu6U3g0NVDDJPO LxtbajwjxY2kNa2l1qhT/ZhKojOye8f/eWXUQhy+idzuJhJac5f76IWFrYppqHo9 AxEtLpV685FKQNyk1AbmcvPbcKplmFCip0P3Amr2IPxJZwiJ30Q= =mI89 -----END PGP SIGNATURE-----