Go to file
Peter Korsgaard 7d708397a9 samba4: security bump to version 4.8.7
Fixes the following security vulnerabilities:

 - CVE-2018-14629:
   All versions of Samba from 4.0.0 onwards are vulnerable to infinite
   query recursion caused by CNAME loops. Any dns record can be added via
   ldap by an unprivileged user using the ldbadd tool, so this is a
   security issue.

 - CVE-2018-16841:
   When configured to accept smart-card authentication, Samba's KDC will call
   talloc_free() twice on the same memory if the principal in a validly signed
   certificate does not match the principal in the AS-REQ.

   This is only possible after authentication with a trusted certificate.

   talloc is robust against further corruption from a double-free with
   talloc_free() and directly calls abort(), terminating the KDC process.

   There is no further vulnerability associated with this issue, merely a
   denial of service.

 - CVE-2018-16851:
   During the processing of an LDAP search before Samba's AD DC returns
   the LDAP entries to the client, the entries are cached in a single
   memory object with a maximum size of 256MB.  When this size is
   reached, the Samba process providing the LDAP service will follow the
   NULL pointer, terminating the process.

   There is no further vulnerability associated with this issue, merely a
   denial of service.

 - CVE-2018-16853:
   A user in a Samba AD domain can crash the KDC when Samba is built in the
   non-default MIT Kerberos configuration.

   With this advisory we clarify that the MIT Kerberos build of the Samba
   AD DC is considered experimental.  Therefore the Samba Team will not
   issue security patches for this configuration.

For more details, see the release notes:

https://www.samba.org/samba/history/samba-4.8.7.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2018-12-03 22:58:05 +01:00
arch arch: add Atom CPUs as Silvermont Architecture target 2018-01-01 13:05:16 +01:00
board configs/imx6sabre: Create distinct pre-processed mkimage config files 2018-11-26 17:57:09 +01:00
boot boot/uboot: fix environment image generation on big endian systems 2018-10-24 13:56:27 +02:00
configs configs/armadeus_apf27: fix U-Boot configuration 2018-11-26 18:02:03 +01:00
docs docs/manual: add external.desc to list of files needed for BR2_EXTERNAL 2018-11-14 23:28:39 +01:00
fs fs/tar: add support for xattrs (thus capabilties) 2018-11-26 17:24:45 +01:00
linux linux: Make dtc install step more reliable 2018-11-26 18:46:54 +01:00
package samba4: security bump to version 4.8.7 2018-12-03 22:58:05 +01:00
support support/graph-depends: fix package names starting with a non-alpha 2018-11-26 18:49:35 +01:00
system skeleton: PAGER without blank and unset at end of for loop 2018-06-17 17:19:52 +02:00
toolchain toolchain/buildroot: fix default of C library choice 2018-05-28 16:12:14 +02:00
utils utils/genrandconfig: add missing new line when creating the configuration 2018-11-26 12:48:13 +01:00
.defconfig arch: remove support for sh64 2016-09-08 22:15:15 +02:00
.flake8 .flake8: add config file for Python code style 2017-10-06 19:05:18 +02:00
.gitignore update gitignore 2013-05-04 12:41:55 +02:00
.gitlab-ci.yml .gitlab-ci.yml: do runtime tests only on explicit trigger 2018-10-26 21:38:10 +02:00
.gitlab-ci.yml.in .gitlab-ci.yml: do runtime tests only on explicit trigger 2018-10-26 21:38:10 +02:00
CHANGES Update for 2018.02.8 2018-11-26 23:41:24 +01:00
Config.in Config.in: security hardening: disable FORTIFY_SOURCE for gcc < 6 2018-11-25 21:48:40 +01:00
Config.in.legacy package/transmission: remove BR2_PACKAGE_TRANSMISSION_REMOTE 2018-06-11 22:57:19 +02:00
COPYING COPYING: add exception about patch licensing 2016-02-26 19:50:13 +01:00
DEVELOPERS woff2: new package 2018-10-05 15:17:08 +02:00
Makefile Update for 2018.02.8 2018-11-26 23:41:24 +01:00
Makefile.legacy Remove BR2_DEPRECATED 2016-10-15 23:14:45 +02:00
README README: add reference to submitting-patches 2016-02-01 19:16:08 +01:00

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches