File _patchinfo of Package patchinfo.2100
<patchinfo incident="2100">
<issue id="953972" tracker="bnc">samba: winbind crash -> netlogon_creds_client_authenticator</issue>
<issue id="953382" tracker="bnc">samba+ssh: no failure message on login try if account is disabled in AD</issue>
<issue id="962177" tracker="bnc">Autogenerated /etc/apparmor.d/local/usr.sbin.smbd-shares is blames samba share with blancspace in name.</issue>
<issue id="968222" tracker="bnc">VUL-0: EMBARGOED: CVE-2015-7560: samba: Getting and setting Windows ACLs on symlinks can change permissions on link target.</issue>
<issue id="966271" tracker="bnc">clustering support not enabled</issue>
<issue id="960249" tracker="bnc">Latest Samba update 4.1.22-21.1 breaks root shares</issue>
<issue id="964023" tracker="bnc">"file has been changed on file system" in eclipse (Windows) on SLES12 samba share</issue>
<issue id="CVE-2015-7560" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>jmcdough</packager>
<description>
This update for the samba server fixes the following issues:
Security issue fixed:
- CVE-2015-7560: Getting and setting Windows ACLs on symlinks can change permissions on link
target; (bso#11648); (bsc#968222).
Other bugs fixed:
- Enable clustering (CTDB) support; (bsc#966271).
- s3: smbd: Fix timestamp rounding inside SMB2 create; (bso#11703);
(bsc#964023).
- vfs_fruit: Fix renaming directories with open files; (bso#11065).
- Fix MacOS finder error 36 when copying folder to Samba; (bso#11347).
- s3:smbd/oplock: Obey kernel oplock setting when releasing oplocks;
(bso#11400).
- Fix copying files with vfs_fruit when using vfs_streams_xattr without
stream prefix and type suffix; (bso#11466).
- s3:libsmb: Correctly initialize the list head when keeping a list of primary
followed by DFS connections; (bso#11624).
- Reduce the memory footprint of empty string options; (bso#11625).
- lib/async_req: Do not install async_connect_send_test; (bso#11639).
- docs: Fix typos in man vfs_gpfs; (bso#11641).
- smbd: make "hide dot files" option work with "store dos attributes = yes";
(bso#11645).
- smbcacls: Fix uninitialized variable; (bso#11682).
- s3:smbd: Ignore initial allocation size for directory creation; (bso#11684).
- Add quotes around path of update-apparmor-samba-profile; (bsc#962177).
- Prevent access denied if the share path is "/"; (bso#11647); (bsc#960249).
- Ensure samlogon fallback requests are rerouted after kerberos failure;
(bsc#953972).
- samba: winbind crash -> netlogon_creds_client_authenticator; (bsc#953972)
</description>
<summary>Security update for samba</summary>
</patchinfo>