This bug was fixed in the package samba - 2:4.3.9+dfsg-0ubuntu1
---
samba (2:4.3.9+dfsg-0ubuntu1) yakkety; urgency=medium
* SECURITY REGRESSION: Updated to 4.3.9 to fix multiple regressions in
the previous security updates. (LP: #1577739)
- debian/control: bump tevent
This bug was fixed in the package samba - 2:4.3.9+dfsg-0ubuntu0.15.10.2
---
samba (2:4.3.9+dfsg-0ubuntu0.15.10.2) wily-security; urgency=medium
* SECURITY REGRESSION: NTLM authentication issues (LP: #1578576)
- debian/patches/samba-bug11912.patch: let msrpc_parse() return
This bug was fixed in the package samba - 2:4.3.9+dfsg-0ubuntu0.16.04.2
---
samba (2:4.3.9+dfsg-0ubuntu0.16.04.2) xenial-security; urgency=medium
* SECURITY REGRESSION: NTLM authentication issues (LP: #1578576)
- debian/patches/samba-bug11912.patch: let msrpc_parse() return
This bug was fixed in the package samba - 2:4.3.9+dfsg-0ubuntu0.14.04.3
---
samba (2:4.3.9+dfsg-0ubuntu0.14.04.3) trusty-security; urgency=medium
* SECURITY REGRESSION: NTLM authentication issues (LP: #1578576)
- debian/patches/samba-bug11912.patch: let msrpc_parse() return
Thanks Marc - appears to work for me!
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report segfault
To manage notifications about this
I have uploaded a test package for trusty that includes the proposed fix
for Samba bug #11914 to the following PPA:
https://launchpad.net/~mdeslaur/+archive/ubuntu/testing
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
** Changed in: samba
Remote watch: Samba Bugzilla #11912 => Samba Bugzilla #11914
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report
It seems there're two similar bugs, I've created
https://bugzilla.samba.org/show_bug.cgi?id=11914 to track the 2nd problem
** Bug watch added: Samba Bugzilla #11914
https://bugzilla.samba.org/show_bug.cgi?id=11914
--
You received this bug notification because you are a member of Ubuntu
Bugs,
Done :)
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report segfault
To manage notifications about this bug go to:
Thanks Paul. Could you please add a comment to the upstream bug?
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report segfault
To
Thanks for testing Paul. Did you update all the binary packages in the
PPA, including winbind and samba-libs, and did you reboot or restart all
processes including squid?
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
Yep - added your testing PPA, then:
sudo apt-get update
sudo apt-get upgrade samba (which brought in all dependencies)
Then rebooted the server for good measure :)
The above error messages were from after the reboot, and I'm still
getting issues when trying to authenticate via the squid proxy.
Just tried and still getting the same problem:
samba:
Installed: 2:4.3.9+dfsg-0ubuntu0.14.04.2~ppa1
Candidate: 2:4.3.9+dfsg-0ubuntu0.14.04.2~ppa1
Version table:
*** 2:4.3.9+dfsg-0ubuntu0.14.04.2~ppa1 0
500 http://ppa.launchpad.net/mdeslaur/testing/ubuntu/ trusty/main amd64
Packages
I have uploaded test packages that include the upstream fix to the
following PPA:
https://launchpad.net/~mdeslaur/+archive/ubuntu/testing
Once they finish building, could someone please test them and confirm it
fixes the issue?
Once someone has tested them successfully, I will publish them as
** Also affects: samba (Ubuntu Xenial)
Importance: Undecided
Status: New
** Also affects: samba (Ubuntu Trusty)
Importance: Undecided
Status: New
** Also affects: samba (Ubuntu Wily)
Importance: Undecided
Status: New
** Changed in: samba (Ubuntu Trusty)
Upstream has a patch in their bug now
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report segfault
To manage notifications about this
** Tags added: regression-update
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report segfault
To manage notifications about this bug
My downgrade command:
aptitude -V install winbind=2:4.1.6+dfsg-1ubuntu2 samba=2:4.1.6+dfsg-
1ubuntu2 libwbclient0=2:4.1.6+dfsg-1ubuntu2 samba-libs=2:4.1.6+dfsg-
1ubuntu2 python-samba=2:4.1.6+dfsg-1ubuntu2 samba-vfs-modules=2:4.1.6
+dfsg-1ubuntu2 libldb1=1:1.1.16-1
** Also affects: samba via
https://bugzilla.samba.org/show_bug.cgi?id=11912
Importance: Unknown
Status: Unknown
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth
Could anyone give a quick guide on how to downgrade samba/winbind to
workaround this issue while it is fixed?
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth
Have submitted to the Samba developers:
https://bugzilla.samba.org/show_bug.cgi?id=11912
** Bug watch added: Samba Bugzilla #11912
https://bugzilla.samba.org/show_bug.cgi?id=11912
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
Could someone who is experiencing this regression with Samba 4.3.9
please report it to the Samba developers here:
https://bugzilla.samba.org/
Please attach the bug report with this one once it's been filed.
I'd file the bug myself, but they may require more details on the
problematic
running an Apache2 server with NTLM authentication against an AD,
stopped working with 500 Internal Server error since the Samba upgrade.
Apache config:
AuthType NTLM
AuthName "..."
NTLMAuth on
NTLMAuthHelper "/usr/bin/ntlm_auth --helper-protocol=squid-.5-ntlmssp"
NTLMBasicAuthoritative on
Same problem. Am running:
Ubuntu Server 14.04.1 LTS
Windbind: 2:4.3.9+dfsg-0ubuntu0.14.04.1
Samba: 2:4.3.9+dfsg-0ubuntu0.14.04.1
Squid3: 3.3.8-1ubuntu6.6
Authenticating against Active Directory - has been working really well
for the last 18 months, then stopped working about a week ago.
Errors
I am seeing the same errors. I am using ntlm_auth for Moodle access.
When attempting to use NTLM, I show this in the processes:
www-data 9866 9856 0 08:52 ?00:00:00 [ntlm_auth]
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to
** Description changed:
System version: Ubuntu 14.04.4 LTS
Squid version: 2:4.3.8+dfsg-0ubuntu0.14.04.2
Winbind version: 2:4.3.8+dfsg-0ubuntu0.14.04.2 upgrade to
2:4.3.9+dfsg-0ubuntu0.14.04.1
My ubuntu server installed Squid to perform http_proxy. Squid auth the
- Active Directory
When I run the commands on the command line they don't exit and pressing
return gives:
ERR
Pressing "?" gives (for ntlmssp, not basic):
BH Query invalid
Typing about anything else gives me (again, only for ntlmssp, not
basic):
BH SPNEGO request invalid prefix
I tried installing gdb and
I can't seem to reproduce this issue. Can someone get a backtrace?
Are you able to reproduce it by using ntlm_auth directly on the command
line, like so?:
$ sudo ntlm_auth --helper-protocol=squid-2.5-basic
MYDOMAIN\testuser mypassword
$ sudo ntlm_auth --helper-protocol=squid-2.5-ntlmssp
Windows AD
i have rolled back and all good now.
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report segfault
To manage notifications
Just so I can try and reproduce this in a test environment, are you
authenticating to a Windows AD, or to a Samba AD?
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth
** Changed in: samba (Ubuntu)
Importance: Undecided => High
** Changed in: samba (Ubuntu)
Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security)
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
Yep, we had to turn off single signon
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
ntlm_auth --helper-protocol=squid-2.5-ntlmssp report segfault
To manage notifications about this
This broke web browsing for my 325 employees this morning. Trying to
research how to roll back to 2:4.1.6+dfsg-1ubuntu2. Please provide
instructions if you can to help others affected. Thanks for reporting
this and your help!
--
You received this bug notification because you are a member of
Status changed to 'Confirmed' because the bug affects multiple users.
** Changed in: samba (Ubuntu)
Status: New => Confirmed
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1578576
Title:
** Description changed:
System version: Ubuntu 14.04.4 LTS
Squid version: 2:4.3.8+dfsg-0ubuntu0.14.04.2
Winbind version: 2:4.3.8+dfsg-0ubuntu0.14.04.2 upgrade to
2:4.3.9+dfsg-0ubuntu0.14.04.1
My ubuntu server installed Squid to perform http_proxy. Squid auth the
Active Directory
35 matches
Mail list logo