From 4c6ab5d85a748e35502d07bb79ad58793febf99b Mon Sep 17 00:00:00 2001 From: Karolin Seeger Date: Thu, 31 Jul 2014 14:48:01 +0200 Subject: [PATCH] WHATSNEW: Add release notes for Samba 4.1.11. Bug: https://bugzilla.samba.org/show_bug.cgi?id=10735 CVE-2014-3560: unstrcpy macro length is invalid Signed-off-by: Karolin Seeger --- WHATSNEW.txt | 55 ++++++++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 52 insertions(+), 3 deletions(-) diff --git a/WHATSNEW.txt b/WHATSNEW.txt index cb9a1c6a47e..521ea1fd0b8 100644 --- a/WHATSNEW.txt +++ b/WHATSNEW.txt @@ -1,4 +1,55 @@ ============================== + Release Notes for Samba 4.1.11 + August 1, 2014 + ============================== + + +This is a security release in order to address +CVE-2014-3560 (Remote code execution in nmbd). + +o CVE-2014-3560: + Samba 4.0.0 to 4.1.10 are affected by a remote code execution attack on + unauthenticated nmbd NetBIOS name services. + + A malicious browser can send packets that may overwrite the heap of + the target nmbd NetBIOS name services daemon. It may be possible to + use this to generate a remote code execution vulnerability as the + superuser (root). + + +Changes since 4.1.10: +--------------------- + +o Volker Lendecke + * BUG 10735: CVE-2014-3560: Fix unstrcpy macro length. + + +####################################### +Reporting bugs & Development Discussion +####################################### + +Please discuss this release on the samba-technical mailing list or by +joining the #samba-technical IRC channel on irc.freenode.net. + +If you do report problems then please try to send high quality +feedback. If you don't provide vital information to help us track down +the problem then you will probably be ignored. All bug reports should +be filed under the Samba 4.1 product in the project's Bugzilla +database (https://bugzilla.samba.org/). + + +====================================================================== +== Our Code, Our Bugs, Our Responsibility. +== The Samba Team +====================================================================== + + +Release notes for older releases follow: +---------------------------------------- + +====================================================================== + + ============================== Release Notes for Samba 4.1.10 July 28, 2014 ============================== @@ -140,10 +191,8 @@ database (https://bugzilla.samba.org/). ====================================================================== -Release notes for older releases follow: ----------------------------------------- +---------------------------------------------------------------------- -====================================================================== ============================= Release Notes for Samba 4.1.9 -- 2.11.4.GIT