[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-12-06 Thread Launchpad Bug Tracker
This bug was fixed in the package samba - 2:4.13.14+dfsg-0ubuntu1 --- samba (2:4.13.14+dfsg-0ubuntu1) jammy; urgency=medium * Update to 4.13.14 as a security update (LP: #1950363) - debian/patches/CVE-2021-20254.patch: removed, included in new version. - debian/control

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-12-06 Thread Marc Deslauriers
** Changed in: samba (Ubuntu Bionic) Status: New => Fix Released ** Changed in: samba (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launc

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-12-02 Thread Marc Deslauriers
I've uploaded updated Bionic packages that fix Samba bug #14901 in the security team's PPA here for testing: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages ** Changed in: samba (Ubuntu Jammy) Status: In Progress => Fix Committed -- You received this bug no

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-30 Thread Marc Deslauriers
That is correct, samba 4.7.6 in bionic is not vulnerable to CVE-2021-23192. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1950363 Title: Nov 2021 security update tracking bug To manage notification

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-30 Thread Kevin Liao
Hi all, I want to ask one question. For CVE-2021-23192, I saw from samba website (https://www.samba.org/samba/security/CVE-2021-23192.html) that it affects only samba 4.10.0 and later. Because what bionic used is samba 4.7.6. Can I say that bionic is not affected by this single CVE? Thanks. -- Y

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-24 Thread Marc Deslauriers
In case we end up having to update bionic to a more recent samba, I've stuck the update package and dependencies in my ppa here: https://launchpad.net/~mdeslaur/+archive/ubuntu/testing/+packages The current plan is to use the update in comment #5. -- You received this bug notification because y

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-23 Thread Marc Deslauriers
There is an updated Samba package for bionic in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages It contains fixes for CVE-2016-2124, CVE-2020-25717, CVE-2020-25722 and CVE-2021-3671 which appear to be the most severe issues. Upstream has

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-11 Thread Marc Deslauriers
Fixing this issue on Ubuntu 18.04 LTS is going to be problematic. The backport to 4.10 of the patchset to fix most of the CVEs contains 686 commits. Backporting that to bionic's 4.7.6 may not be feasible. The main issue with updating bionic to 4.13.14 is the lack of support for python 2.7. I have

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-11 Thread Launchpad Bug Tracker
This bug was fixed in the package samba - 2:4.13.14+dfsg-0ubuntu0.20.04.1 --- samba (2:4.13.14+dfsg-0ubuntu0.20.04.1) focal-security; urgency=medium * Update to 4.13.14 as a security update (LP: #1950363) - Removed patches included in new version: + CVE-*.patch + zer

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-11 Thread Launchpad Bug Tracker
This bug was fixed in the package samba - 2:4.13.14+dfsg-0ubuntu0.21.04.1 --- samba (2:4.13.14+dfsg-0ubuntu0.21.04.1) hirsute-security; urgency=medium * Update to 4.13.14 as a security update (LP: #1950363) - debian/patches/CVE-2021-20254.patch: removed, included in new ve

[Bug 1950363] Re: Nov 2021 security update tracking bug

2021-11-11 Thread Launchpad Bug Tracker
This bug was fixed in the package samba - 2:4.13.14+dfsg-0ubuntu0.21.10.1 --- samba (2:4.13.14+dfsg-0ubuntu0.21.10.1) impish-security; urgency=medium * Update to 4.13.14 as a security update (LP: #1950363) - debian/patches/CVE-2021-20254.patch: removed, included in new ver