Name
samba
Version
4.23.5
Type
library
Description
-
Licenses
GPL-3.0-or-later & LGPL-3.0-or-later & GPL-2.0-or-later
PURL
-
CPE
cpe:2.3:*:samba:samba:4.23.5:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
Don't check xsltproc manpages
Bian Naimeng <biannm@cn.fujitsu.com>
2
smbtorture: skip test case tfork_cmd_send
Yi Zhao <yi.zhao@windriver.com>
3
Lifted from gentoo and ported to 4.4.5
Khem Raj <raj.khem@gmail.com>
4
Fix pyext_PATTERN for cross compilation
Yi Zhao <yi.zhao@windriver.com>
5
lib:replace: Add test for memset_explicit()
Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
6
Add options to configure the use of libbsd
Peter Kjellerstedt <pkj@axis.com>
7
Add config option without-valgrind
Changqing Li <changqing.li@windriver.com>
8
Replace memset_s() with memset_explicit()
Andreas Schneider <asn@samba.org>
9
lib:replace: Implement memset_explicit()
Andreas Schneider <asn@samba.org>
10
lib:replace: Remove memset_s()
Andreas Schneider <asn@samba.org>
11
Musl does not have _r versions of getent() and getpwent()
Khem Raj <raj.khem@gmail.com>
12
Deleted settiong of python to fix the install conflict error
Lei Maohui <leimaohui@fujitsu.com>
13
do not import target module while cross compile
Changqing Li <changqing.li@windriver.com>
Vulnerabilities#
Name
Analysis
Description
Exploitable
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
False Positive
Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors.