mirror of
https://github.com/samba-team/samba.git
synced 2025-01-03 01:18:10 +03:00
WHATSNEW: Add release notes for Samba 4.16.10.
Signed-off-by: Jule Anger <janger@samba.org>
This commit is contained in:
parent
6736fc0cff
commit
62390bac92
63
WHATSNEW.txt
63
WHATSNEW.txt
@ -1,3 +1,63 @@
|
||||
===============================
|
||||
Release Notes for Samba 4.16.10
|
||||
March 29, 2023
|
||||
===============================
|
||||
|
||||
|
||||
This is a security release in order to address the following defects:
|
||||
|
||||
o CVE-2023-0922: The Samba AD DC administration tool, when operating against a
|
||||
remote LDAP server, will by default send new or reset
|
||||
passwords over a signed-only connection.
|
||||
https://www.samba.org/samba/security/CVE-2023-0922.html
|
||||
|
||||
o CVE-2023-0614: The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919
|
||||
Confidential attribute disclosure via LDAP filters was
|
||||
insufficient and an attacker may be able to obtain
|
||||
confidential BitLocker recovery keys from a Samba AD DC.
|
||||
Installations with such secrets in their Samba AD should
|
||||
assume they have been obtained and need replacing.
|
||||
https://www.samba.org/samba/security/CVE-2023-0614.html
|
||||
|
||||
|
||||
Changes since 4.16.9
|
||||
--------------------
|
||||
|
||||
o Andrew Bartlett <abartlet@samba.org>
|
||||
* BUG 15270: VE-2023-0614.
|
||||
* BUG 15331: ldb wildcard matching makes excessive allocations.
|
||||
* BUG 15332: large_ldap test is inefficient.
|
||||
|
||||
o Rob van der Linde <rob@catalyst.net.nz>
|
||||
* BUG 15315: CVE-2023-0922.
|
||||
|
||||
o Joseph Sutton <josephsutton@catalyst.net.nz>
|
||||
* BUG 15270: CVE-2023-0614.
|
||||
|
||||
|
||||
#######################################
|
||||
Reporting bugs & Development Discussion
|
||||
#######################################
|
||||
|
||||
Please discuss this release on the samba-technical mailing list or by
|
||||
joining the #samba-technical:matrix.org matrix room, or
|
||||
#samba-technical IRC channel on irc.libera.chat.
|
||||
|
||||
If you do report problems then please try to send high quality
|
||||
feedback. If you don't provide vital information to help us track down
|
||||
the problem then you will probably be ignored. All bug reports should
|
||||
be filed under the Samba 4.1 and newer product in the project's Bugzilla
|
||||
database (https://bugzilla.samba.org/).
|
||||
|
||||
|
||||
======================================================================
|
||||
== Our Code, Our Bugs, Our Responsibility.
|
||||
== The Samba Team
|
||||
======================================================================
|
||||
|
||||
|
||||
Release notes for older releases follow:
|
||||
----------------------------------------
|
||||
==============================
|
||||
Release Notes for Samba 4.16.9
|
||||
February 16, 2023
|
||||
@ -72,8 +132,7 @@ database (https://bugzilla.samba.org/).
|
||||
======================================================================
|
||||
|
||||
|
||||
Release notes for older releases follow:
|
||||
----------------------------------------
|
||||
----------------------------------------------------------------------
|
||||
==============================
|
||||
Release Notes for Samba 4.16.8
|
||||
December 15, 2022
|
||||
|
Loading…
Reference in New Issue
Block a user