Re: fixing CVE-2018-1050 in samba 3.3.6

2018-03-23 Thread Holger Levsen
On Thu, Mar 22, 2018 at 04:40:15PM +0100, Mathieu Parent wrote: > Have you seen my mail at: > https://lists.debian.org/debian-lts/2018/03/msg00047.html yes, it made me investigate this… > I agree that a fix is needed for wheezy-lts. ok. > I've added a comment in the bug about 3.6 being affecte

Re: fixing CVE-2018-1050 in samba 3.3.6

2018-03-22 Thread Mathieu Parent
2018-03-21 23:01 GMT+01:00 Holger Levsen : > Dear samba maintainers, Hello, > the fix for CVE-2018-1050 (eg from 4.5.12+dfsg-2+deb9u) applies cleanly > on 3.6.6-6+deb7u15, however CVE-2018-1050 says that only versions >4.0.0 > are affected. > > Since (afaics) there is no known exploit I cannot re