Date: Tue, 3 Sep 2019 23:32:13 +0000 (UTC) From: "Timur I. Bakeyev" <timur@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r511050 - head/security/vuxml Message-ID: <201909032332.x83NWD1A008358@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: timur Date: Tue Sep 3 23:32:13 2019 New Revision: 511050 URL: https://svnweb.freebsd.org/changeset/ports/511050 Log: Add entry about CVE-2019-10197 On a Samba SMB server for all versions of Samba from 4.9.0 clients are able to escape outside the share root directory if certain configuration parameters set in the smb.conf file. Security: CVE-2019-10197 Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Tue Sep 3 23:25:25 2019 (r511049) +++ head/security/vuxml/vuln.xml Tue Sep 3 23:32:13 2019 (r511050) @@ -58,6 +58,34 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="145a3e17-cea2-11e9-81e2-005056a311d1"> + <topic>samba -- combination of parameters and permissions can allow user to escape from the share path definition</topic> + <affects> + <package> + <name>samba410</name> + <range><lt>4.10.8</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The samba project reports:</p> + <blockquote cite="https://www.samba.org/samba/security/CVE-2019-10197.html"> + <p>On a Samba SMB server for all versions of Samba from 4.9.0 clients are + able to escape outside the share root directory if certain + configuration parameters set in the smb.conf file.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2019-10197</cvename> + <url>https://www.samba.org/samba/security/CVE-2019-10197.html</url> + </references> + <dates> + <discovery>2019-09-01</discovery> + <entry>2019-09-03</entry> + </dates> + </vuln> + <vuln vid="05463e0a-abd3-4fa4-bd5f-cd5ed132d4c6"> <topic>mozilla -- multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201909032332.x83NWD1A008358>