HomeFreeBSD

Security update for net/samba410

Description

Security update for net/samba410

o CVE-2019-10218:

Malicious servers can cause Samba client code to return filenames containing
path separators to calling code.

o CVE-2019-14833:

When the password contains multi-byte (non-ASCII) characters, the check
password script does not receive the full password string.

o CVE-2019-14847:

Users with the "get changes" extended access right can crash the AD DC LDAP
server by requesting an attribute using the range= syntax.

Security: CVE-2019-10218

		CVE-2019-14833
		CVE-2019-14847

Sponsored by: my wife

Details

Provenance
timurAuthored on
Parents
rP516122: Add entry about Samba vulnerabilities
Branches
Unknown
Tags
Unknown