Hello community, here is the log from the commit of package samba.2357 for openSUSE:13.1:Update checked in at 2013-12-19 17:16:42 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:13.1:Update/samba.2357 (Old) and /work/SRC/openSUSE:13.1:Update/.samba.2357.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "samba.2357" Changes: -------- New Changes file: --- /dev/null 2013-11-25 01:44:08.036031256 +0100 +++ /work/SRC/openSUSE:13.1:Update/.samba.2357.new/samba.changes 2013-12-19 17:16:45.000000000 +0100 @@ -0,0 +1,8984 @@ +------------------------------------------------------------------- +Mon Dec 9 10:48:06 UTC 2013 - [email protected] + +- Update to 4.1.3. + + DCE-RPC fragment length field is incorrectly checked; CVE-2013-4408; + (bnc#844720). + + pam_winbind login without require_membership_of restrictions; + CVE-2012-6150; (bnc#853347). + +------------------------------------------------------------------- +Fri Dec 6 16:25:59 UTC 2013 - [email protected] + +- Make use of the full gpg pub key file name including the key ID. + +------------------------------------------------------------------- +Thu Dec 5 19:22:47 UTC 2013 - [email protected] + +- Add transparent file compression support; (fate#316266). + + Implement FSCTL_GET_COMPRESSION and FSCTL_SET_COMPRESSION handlers. + + Add FILE_ATTRIBUTE_COMPRESSED and FILE_NO_COMPRESSION support. + + Extend vfs_btrfs VFS module to utilize get/set compression hooks. + +------------------------------------------------------------------- +Thu Dec 5 17:03:34 UTC 2013 - [email protected] + +- Add support for FSCTL_SRV_COPYCHUNK_WRITE; (fate#314770). + +------------------------------------------------------------------- +Mon Dec 2 15:50:56 UTC 2013 - [email protected] + +- Remove bogus libsmbclient0 package description and cleanup the libsmbclient + line from baselibs.conf; (bnc#853021). + +------------------------------------------------------------------- +Fri Nov 22 11:11:42 UTC 2013 - [email protected] + +- BuildRequire systemd on post-12.2 systems. + +------------------------------------------------------------------- +Fri Nov 22 10:32:30 UTC 2013 - [email protected] + +- Update to 4.1.2. + + s4-dns: dlz_bind9: Create dns-HOSTNAME account disabled; (bso#9091). + + dfs_server: Use dsdb_search_one to catch 0 results as well as + NO_SUCH_OBJECT errors; (bso#10052). + + Missing talloc_free can leak stackframe in error path; (bso#10187). + + Fix memset used with constant zero length parameter; (bso#10190). + + s4:dsdb/rootdse: report 'dnsHostName' instead of 'dNSHostName'; + (bso#10193). + + Make offline logon cache updating for cross child domain group membership; + (bso#10194). + + nsswitch: Fix short writes in winbind_write_sock; (bso#10195). + + RW Deny for a specific user is not overriding RW Allow for a group; + (bso#10196). + + vfs_glusterfs: Fix excessive debug output from vfs_gluster_open(); + (bso#10224). + + vfs_glusterfs: Implement proper mashalling/unmarshalling of ACLs; + (bso#10224). + + VFS plugin was sending the actual size of the volume instead of the total + number of block units because of which windows was getting the wrong + volume capacity; (bso#10224). + + libcli/smb: Fix smb2cli_ioctl*() against Windows 2008; (bso#10232). + + xattr: Fix listing EAs on *BSD for non-root users; (bso#10247). + + Fix the build of vfs_glusterfs; (bso#10253). + + s3-winbindd: Fix cache_traverse_validate_fn failure for NDR cache entries; + (bso#10264). + + util: Remove 32bit macros breaking strict aliasing; (bso#10269). + +------------------------------------------------------------------- +Thu Nov 21 17:16:42 UTC 2013 - [email protected] + +- Let gpg verify execution condition not fail on non SUSE systems. + +------------------------------------------------------------------- +Thu Nov 21 14:13:37 UTC 2013 - [email protected] + +- Add systemd support for post-12.2 systems. + +------------------------------------------------------------------- +Fri Nov 15 18:04:50 UTC 2013 - [email protected] + +- Unconditionally create the CUPS smb backend sym link pointing to smbspool; + (bnc#850656). + +------------------------------------------------------------------- +Wed Nov 13 15:16:03 UTC 2013 - [email protected] + +- Update to 4.1.1. + + ACLs are not checked on opening an alternate data stream on a file or + directory; CVE-2013-4475; (bso#10229); (bnc#848101). + + Private key in key.pem world readable; CVE-2013-4476; (bnc#848103). + +------------------------------------------------------------------- +Sun Nov 10 18:16:56 UTC 2013 - [email protected] + +- Private key in key.pem world readable; CVE-2013-4476; (bnc#848103). + +------------------------------------------------------------------- +Wed Oct 30 14:11:42 UTC 2013 - [email protected] + +- ACLs are not checked on opening an alternate data stream on a file or + directory; CVE-2013-4475; (bso#10229); (bnc#848101). + +------------------------------------------------------------------- +Fri Oct 11 08:58:29 UTC 2013 - [email protected] + +- Update to 4.1.0. + + pam_winbindd: Support the KEYRING ccache type; (bso#10132). + + Fix PAC parsing failure; (bso#10178). + +------------------------------------------------------------------- +Wed Oct 9 20:41:52 UTC 2013 - [email protected] + +- Unify the defattr lines in the pidl, python, test and test-devel files + section by removing the optional directory mode. + +------------------------------------------------------------------- +Wed Oct 9 15:30:31 UTC 2013 - [email protected] + +- Verify source tar ball gpg signature. + +------------------------------------------------------------------- +Fri Sep 27 12:30:24 UTC 2013 - [email protected] + +- Update to 4.1.0rc4. + + dsdb: Convert the full string from UTF16 to UTF8, including embedded + NULLs; (bso#8077). + + python-samba-tool fsmo: Do not give an error on a successful role + transfer; (bso#9461). + + dbwrap_ctdb: Treat empty records as non-existing; (bso#10008). + + Raise the level of a debug when unable to open a printer; (bso#10118). + + Add "acl allow execute always" parameter; (bso#10134). + + vfs_shadow_copy2: Display previous versions correctly over SMB2; + (bso#10137). + + smbd: Always clean up share modes after hard crash; (bso#10138). + + Valid utf8 filenames cause "invalid conversion error" messages; + (bso#10139). + + libcli/smb: Use SMB1 MID=0 for the initial Negprot; (bso#10144). + + Samba SMB2 client code reads the wrong short name length in a directory + listing reply; (bso#10145). + + libcli/smb: Only check the SMB2 session setup signature if required and + valid; (bso#10146). + + Better document potential implications of a globally used "valid users"; + (bso#10147). + + cli_smb2_get_ea_list_path() failed to close file on exit; (bso#10149). + + Not all OEM servers support the ALTNAME info level; (bso#10150). + + Regression causes replication failure with Windows 2008R2 and deletes + Deleted Objects; (bso#10157). + + Netbios related samba process consumes 100% CPU; (bso#10158). + + Fix POSIX ACL mapping when setting DENY ACE's from Windows; (bso#10162). + +------------------------------------------------------------------- +Thu Sep 19 22:10:11 UTC 2013 - [email protected] + +- Require libndr-standard-devel due to gen_ndr/lsa.h from libpdb-devel. + +------------------------------------------------------------------- +Mon Sep 16 12:49:02 UTC 2013 - [email protected] + +- Add libdcerpc0, libdcerpc-atsvc0, libdcerpc-binding0, libdcerpc-samr0, + libgensec0, libndr0, libndr-krb5pac0, libndr-nbt0, libndr-standard0, + libpdb0, libregistry0, libsamba-credentials0, libsamba-hostconfig0, + libsamba-policy0, libsamba-util0, libsamdb0, libsmbclient-raw0, libsmbconf0, + libsmbldap0, and libtevent-util0 to baselibs.conf. + +------------------------------------------------------------------- +Sat Sep 14 17:05:05 UTC 2013 - [email protected] + +- Add or polish the shared library package summaries and descriptions. + +------------------------------------------------------------------- +Fri Sep 13 09:24:47 UTC 2013 - [email protected] + +- Update to 4.1.0rc3. + + Fix working on site with Read Only Domain Controller; (bso#5917). + + Add man page for vfs_syncops; (bso#7364). + + Add man page for vfs_linux_xfs_sgid; (bso#7490). + + When replicating DNS for bind9_dlz we need to create the server-DNS + account remotely; (bso#9091). + + Winbind unable to retrieve user information from AD; (bso#9615). + + winbind_lookup_names() fails because of NT_STATUS_CANT_ACCESS_DOMAIN_INFO; + (bso#9899). + + Build Samba 4.0.x on AIX with IBM XL C/C++; (bso#9911). + + Add SMB2 and SMB3 support for smbclient; (bso#9974). + + Add man pages for ntdb tools; (bso#10000). + + Add man page for samba-regedit tool; (bso#10001). + + ::1 added to nameserver on join; (bso#10030). + + Fix memory leak in source3/lib/util.c:1493; (bso#10063). + + Fix segmentation fault in 'net ads join'; (bso#10073). + + Fix variable list in vfs_crossrename man page; (bso#10076). + + s3-winbind: Fix a segfault passing NULL to a fstring argument; (bso#10082). + + smbd: Fix async echo handler forking; (bso#10086). + + MacOSX 10.9 will not follow path-based DFS referrals handed out by Samba; + (bso#10097). + + Honour output buffer length set by the client for SMB2 GetInfo requests; + (bso#10106). + + Fix Winbind crashes on DC with trusted AD domains; (bso#10107). ++++ 8787 more lines (skipped) ++++ between /dev/null ++++ and /work/SRC/openSUSE:13.1:Update/.samba.2357.new/samba.changes New: ---- baselibs.conf patches.tar.bz2 samba-4.1.3.tar.asc samba-4.1.3.tar.gz samba-client-rpmlintrc samba-pubkey.asc samba-pubkey_6568B7EA.asc samba.changes samba.spec vendor-files.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ samba.spec ++++++ ++++ 2491 lines (skipped) ++++++ baselibs.conf ++++++ libdcerpc0 libdcerpc-atsvc0 libdcerpc-binding0 libdcerpc-samr0 libgensec0 libldb1 libndr0 libndr-krb5pac0 libndr-nbt0 libndr-standard0 libnetapi0 libpdb0 libregistry0 libsamba-credentials0 libsamba-hostconfig0 libsamba-policy0 libsamba-util0 libsamdb0 # The next line is required for pre-11.0 builds of libsmbclient libsmbclient libsmbclient0 libsmbclient-raw0 libsmbconf0 libsmbldap0 libtalloc2 libtdb1 libtevent0 libtevent-util0 libwbclient0 samba supplements "packageand(samba:pam-<targettype>)" -/usr/lib/samba samba-winbind supplements "packageand(samba-winbind:pam-<targettype>)" supplements "packageand(samba-winbind:glibc-<targettype>)" -/usr/lib/samba samba-client supplements "packageand(samba-client:glibc-<targettype>)" -/usr/lib/samba samba-libs ++++++ samba-client-rpmlintrc ++++++ addFilter("shlib-policy-name-error") ++++++ samba-pubkey.asc ++++++ pub 1024D/6568B7EA 2007-02-04 [expires: 2014-02-25] uid Samba Distribution Verification Key <[email protected]> sub 2048g/DA6DFB44 2007-02-04 [expires: 2014-02-25] -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.4.11 (GNU/Linux) mQGiBEXGOUcRBACooMht/2pmNT3bKZn1WEFQa+sXe6nxi3G6lH5bIBUKp85SDM57 4qTcBIJXhwfGABeSvyUdZJbBxJDD5bNiO4k+Y5j3t8t9hb2FKgJ1bXL2aO5BbFnJ UlkWw8UnHE3A3mmq2hYjfu+0J7mdMxyH5kajbtGfgt0rbPn/K00AgoBCqwCgyNR7 1kaKzs1os6BiBhu0sTxTkN8EAJC1u1+z9mput/IWo9bQ85KRPfTXXRxv07jK++Yf tPGMerJFxdpdVI+O+LQB9J7L6WUHF8TzmMEGHHStjnKiZB3PCDcAYpR8pVB3085f fEpF32ic7mQzK+K+P0KARadywX1JLYSYP2YQ1BeYteC7hUtp/U0i0c12JDG4Bmil JMZABACis5ms470DH3OwU7b32lDDLFWlwGEQX+OKQealhYgz3hdIzO+cm6Gz0/z1 YGl8oV0dc1tG2EfsndDx7QRwrBoxahfsgClN4K8HLtbBy1Ox9kZn+hr1yNEaPdko +W5bC96Wo2RqnSP09qJ5/tp6rXXCLIgF/+PeCJtP31MaMP0Jo7Q6U2FtYmEgRGlz dHJpYnV0aW9uIFZlcmlmaWNhdGlvbiBLZXkgPHNhbWJhLWJ1Z3NAc2FtYmEub3Jn PohmBBMRAgAmAhsDBgsJCAcDAgQVAggDBBYCAwECHgECF4AFAk9Ki3oFCQ1GuTMA CgkQbzORW2Vot+oKMQCgxTZ6Gvo6cJsVdVLzUiJPcHD9tW4AnjiOTF6F0G60oPK0 IxKOjGvVQ+4riEYEEBECAAYFAkXGOXUACgkQXNXaBxV7yV6oTwCgnSEFCs2pAwW5 LU22AfVDwh9e5AkAn2k0dRoGj2UL/Js4qvf3sBqEw4rriEYEEBECAAYFAkXGOcYA CgkQIR7qMdg1EfZyDACgyvRXAmV0XUhH1vbNMEG9+sFXaCwAoOQTsk19i3Luy3Pw +1gDaUeCzeLdiEYEEBECAAYFAkXIMMUACgkQ3L4Y/6A1U7wMMACgg4+AVtovhtY6 y1qip9uZ8qwbnkkAni269FhHSPKfGGEnfkrN/Q2/3EY7iEYEEBECAAYFAkYNcugA CgkQp6cLM3ld2XFzGwCffyD/eMhEKCN6j5FCSbb3rhkyR/kAn0PlFtYrTNkrc1dO ezhvaZZCPBHWiEYEEBECAAYFAkZQmboACgkQVVCoNUmKuAcl1wCdEzFgS3DIgIhY y6Id5a9EqUjArLkAnArdjXskM952gLuyJjgictCiHdIeiEYEEBECAAYFAkZdvkMA CgkQw1Ohknblb7ZN8gCgjD/SWG0qBCBD7w19I5kVTijU9j4AmwbPf4wU7hY942tn 1NxUyKwF+edxuQINBEXGOWEQCADIOV4TpVG6tDXU7YD1VjJ39xduomiWTg94dIOD g1bZHLvwUa5I1X7zsjYmghZ5Qa6WxNknbRywWnaP0POMXSMspVWnqBQTZknxdApM bMQEko0pPJSLwdTD3+0y5ht4edf08asWdSBT5yvu5Oak4O/Sa3P5lNIe8Q3SjfqR YiSX12uWgqeh+2JsQC50Lr9rnz9AMjKqZEx2v7XKnCkxoaFy1XwOpPjJtIuPFaSI 5OunNsuhXYeGQv7MqqA2RNuulonoHgl9J6YzRBjdmDB28Lm+JKXyJpnHDrUkK6c5 04EuxVXXQKOvLNPwod3U89OCZ3gFZU/zeESQdpWxXMiQvUqPAAQLCACnbn0cYaXh l3UnnQgyPYVUJV12/sAjhlgAQq08SPgTJp4GE/Jx9C2KMS7dlWYH4tjDSbeO+RLL d26npdhiy8Cn9UvsJvDs71/+5S2PTpV16eH5QzQZkvJ/PXkkRXQ1Ilovkvt5rKie HCx4n6QZb5td9AuAeRZp75UXERO7pXKG/57o/SzswrD/tSEKRpBKQED4eHsPohLw 3dMKDWG6hLRf4GR8v+xKLFivqXr3ttELb9xS7ZyZqz6FSFucQAp6XY/xjnR3CFzf Kq9pHO4PwvhU53uQeI9suAHSPecxfUIcQfrCaN6K6ktEMY+KxeTJUgqB7Fnskqyn Cof0MN2OA40+iE8EGBECAA8CGwwFAk9Ki+YFCQ1GuYUACgkQbzORW2Vot+poJACe Mx7cSix0y3zIgTvAIty06thlOMUAn1hZdeMtAkWjaKfu8LWk/umBetPI =49fm -----END PGP PUBLIC KEY BLOCK----- ++++++ samba-pubkey_6568B7EA.asc ++++++ pub 1024D/6568B7EA 2007-02-04 [expires: 2014-02-25] uid Samba Distribution Verification Key <[email protected]> sub 2048g/DA6DFB44 2007-02-04 [expires: 2014-02-25] -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.4.11 (GNU/Linux) mQGiBEXGOUcRBACooMht/2pmNT3bKZn1WEFQa+sXe6nxi3G6lH5bIBUKp85SDM57 4qTcBIJXhwfGABeSvyUdZJbBxJDD5bNiO4k+Y5j3t8t9hb2FKgJ1bXL2aO5BbFnJ UlkWw8UnHE3A3mmq2hYjfu+0J7mdMxyH5kajbtGfgt0rbPn/K00AgoBCqwCgyNR7 1kaKzs1os6BiBhu0sTxTkN8EAJC1u1+z9mput/IWo9bQ85KRPfTXXRxv07jK++Yf tPGMerJFxdpdVI+O+LQB9J7L6WUHF8TzmMEGHHStjnKiZB3PCDcAYpR8pVB3085f fEpF32ic7mQzK+K+P0KARadywX1JLYSYP2YQ1BeYteC7hUtp/U0i0c12JDG4Bmil JMZABACis5ms470DH3OwU7b32lDDLFWlwGEQX+OKQealhYgz3hdIzO+cm6Gz0/z1 YGl8oV0dc1tG2EfsndDx7QRwrBoxahfsgClN4K8HLtbBy1Ox9kZn+hr1yNEaPdko +W5bC96Wo2RqnSP09qJ5/tp6rXXCLIgF/+PeCJtP31MaMP0Jo7Q6U2FtYmEgRGlz dHJpYnV0aW9uIFZlcmlmaWNhdGlvbiBLZXkgPHNhbWJhLWJ1Z3NAc2FtYmEub3Jn PohmBBMRAgAmAhsDBgsJCAcDAgQVAggDBBYCAwECHgECF4AFAk9Ki3oFCQ1GuTMA CgkQbzORW2Vot+oKMQCgxTZ6Gvo6cJsVdVLzUiJPcHD9tW4AnjiOTF6F0G60oPK0 IxKOjGvVQ+4riEYEEBECAAYFAkXGOXUACgkQXNXaBxV7yV6oTwCgnSEFCs2pAwW5 LU22AfVDwh9e5AkAn2k0dRoGj2UL/Js4qvf3sBqEw4rriEYEEBECAAYFAkXGOcYA CgkQIR7qMdg1EfZyDACgyvRXAmV0XUhH1vbNMEG9+sFXaCwAoOQTsk19i3Luy3Pw +1gDaUeCzeLdiEYEEBECAAYFAkXIMMUACgkQ3L4Y/6A1U7wMMACgg4+AVtovhtY6 y1qip9uZ8qwbnkkAni269FhHSPKfGGEnfkrN/Q2/3EY7iEYEEBECAAYFAkYNcugA CgkQp6cLM3ld2XFzGwCffyD/eMhEKCN6j5FCSbb3rhkyR/kAn0PlFtYrTNkrc1dO ezhvaZZCPBHWiEYEEBECAAYFAkZQmboACgkQVVCoNUmKuAcl1wCdEzFgS3DIgIhY y6Id5a9EqUjArLkAnArdjXskM952gLuyJjgictCiHdIeiEYEEBECAAYFAkZdvkMA CgkQw1Ohknblb7ZN8gCgjD/SWG0qBCBD7w19I5kVTijU9j4AmwbPf4wU7hY942tn 1NxUyKwF+edxuQINBEXGOWEQCADIOV4TpVG6tDXU7YD1VjJ39xduomiWTg94dIOD g1bZHLvwUa5I1X7zsjYmghZ5Qa6WxNknbRywWnaP0POMXSMspVWnqBQTZknxdApM bMQEko0pPJSLwdTD3+0y5ht4edf08asWdSBT5yvu5Oak4O/Sa3P5lNIe8Q3SjfqR YiSX12uWgqeh+2JsQC50Lr9rnz9AMjKqZEx2v7XKnCkxoaFy1XwOpPjJtIuPFaSI 5OunNsuhXYeGQv7MqqA2RNuulonoHgl9J6YzRBjdmDB28Lm+JKXyJpnHDrUkK6c5 04EuxVXXQKOvLNPwod3U89OCZ3gFZU/zeESQdpWxXMiQvUqPAAQLCACnbn0cYaXh l3UnnQgyPYVUJV12/sAjhlgAQq08SPgTJp4GE/Jx9C2KMS7dlWYH4tjDSbeO+RLL d26npdhiy8Cn9UvsJvDs71/+5S2PTpV16eH5QzQZkvJ/PXkkRXQ1Ilovkvt5rKie HCx4n6QZb5td9AuAeRZp75UXERO7pXKG/57o/SzswrD/tSEKRpBKQED4eHsPohLw 3dMKDWG6hLRf4GR8v+xKLFivqXr3ttELb9xS7ZyZqz6FSFucQAp6XY/xjnR3CFzf Kq9pHO4PwvhU53uQeI9suAHSPecxfUIcQfrCaN6K6ktEMY+KxeTJUgqB7Fnskqyn Cof0MN2OA40+iE8EGBECAA8CGwwFAk9Ki+YFCQ1GuYUACgkQbzORW2Vot+poJACe Mx7cSix0y3zIgTvAIty06thlOMUAn1hZdeMtAkWjaKfu8LWk/umBetPI =49fm -----END PGP PUBLIC KEY BLOCK----- -- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
