-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4513-1 security@xxxxxxxxxx https://www.debian.org/security/ Salvatore Bonaccorso September 03, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : samba CVE ID : CVE-2019-10197 Stefan Metzmacher discovered a flaw in Samba, a SMB/CIFS file, print, and login server for Unix. Specific combinations of parameters and permissions can allow user to escape from the share path definition and see the complete '/' filesystem. Unix permission checks in the kernel are still enforced. Details can be found in the upstream advisory at https://www.samba.org/samba/security/CVE-2019-10197.html For the stable distribution (buster), this problem has been fixed in version 2:4.9.5+dfsg-5+deb10u1. We recommend that you upgrade your samba packages. For the detailed security status of samba please refer to its security tracker page at: https://security-tracker.debian.org/tracker/samba Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl1u2PlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QpmhAAlfRkvD9vRf5Ygq8eG5nzZRuoLum8yWfzA1/TxI93u+arlw7fIPvnzWNB s0uDcCaltqc/tsI3V0WjKKZ3hiop0WdEMgQ4ZY5Smo2iZrAZAFgsOUHwf8aToG3n r/j5eJ7E3gKk4IibinDY/iJzCPWKwwFB/0R3qiNFNRAtzvavci06BAMARGkHxAcZ sITXN5gDgCNbU0gzWNRD6NkTRVBZ+tF5/IAKAv+y+Wgq+QTXLWfTzJgi4TjUeTVY oFVKDPeO5N3sjp0plkZkSkwmzRGlv4DtUXKwEpScPVZuMms4AOH7ca+zMomTkhOn xVmEMOsmlNDyTJnHEHKNLKTc3nrKG0NTkyAf7QDmquwl5FVlrgIUui0fzxp/qRHE gbOSTW4OOk7cLK9wro01COk3FGB5nqTUO2qkDBRA/R3g4rJyu2WEBSY0aAq6J4Ht 6w7XNrbrj6hEaBKo4tToYVI+bE3KBZSY/imsYTyvdzVVksqcPe4S0NuK4WkDGMer veJk1YSc5FNdPeCsxM9z5+0v8If81wyWaiECiuadTb9vR78vCO4XtcayJfPy9mTK KCKs81lbcReA9gayr+L88MjeYVfFGRCpnFh3CXDTznFdNN87guR0BpdNbZcoHJ+v tQzndSbwVCnfOwCZyS/krD8AJfRQCKXZy2fdAAX7saQjvV0nKq4= =YjR/ -----END PGP SIGNATURE-----