NEWS[4.17.2]: Samba 4.17.2, 4.16.6 and 4.15.11 Security Releases Available for Download
[samba-web.git] / history / security.html
1 <!--#include virtual="/samba/header.html" --> 
2   <title>Samba - Security Updates and Information</title>
3 <!--#include virtual="header_history.html" -->
4
5 <h2>Samba Security Releases</h2>
6
7     <p>Security releases for Samba are listed below by their release
8 date. The previously affected versions of Samba are listed alongside
9 the appropriate security concern. For complete information, follow the
10 link to full release notes for each release.</p>
11
12    <p>Samba's <a href="https://wiki.samba.org/index.php/Samba_Security_Process">
13       coordinated security release and disclosure process</a> is followed
14       and new versions of Samba are released for
15       <a href="https://wiki.samba.org/index.php/Samba_Release_Planning">
16       supported Samba versions</a>.</p>
17
18    <p>A list of public <a href="https://bugzilla.samba.org/buglist.cgi?f1=alias&o1=regexp&order=Last Changed&product=PIDL&product=Samba 2.2&product=Samba 3.0&product=Samba 3.2&product=Samba 3.3&product=Samba 3.4&product=Samba 3.5&product=Samba 3.6&product=Samba 4.0&product=Samba 4.1 and newer&query_format=advanced&v1=^CVE-.*">
19       Samba Security Bugs</a> is available.  Some minor issues will
20       only be listed in <a href="https://bugzilla.samba.org">
21       The Samba Bugzilla</a> and not here, if they did not result
22       in a security release</p>
23
24     <table class="security_table">
25       <th colspan="6">Samba Security Releases</th>
26       <tr >
27         <td><em>Date Issued</em></td>
28         <td><em>Download</em></td>
29         <td><em>Known Issue(s)</em></td>
30         <td><em>Affected Releases</em></td>
31         <td><em>CVE ID #</em></td>
32         <td><em>Details</em></td>
33       </tr>
34
35     <tr>
36         <td>25 October 2022</td>
37         <td><a href="/samba/ftp/patches/security/samba-4.17.2-security-2022-10-25.patch">
38         patch for Samba 4.17.2</a><br />
39         <a href="/samba/ftp/patches/security/samba-4.16.6-security-2022-10-25.patch">
40         patch for Samba 4.16.6</a><br />
41         <a href="/samba/ftp/patches/security/samba-4.15.11-security-2022-10-25.patch">
42         patch for Samba 4.15.11</a><br />
43         </td>
44         <td>CVE-2022-3437 and CVE-2022-3592.
45         Please see announcements for details.
46         </td>
47         <td>Please refer to the advisories.</td>
48         <td>
49 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3437">CVE-2022-3437</a>, 
50 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3592">CVE-2022-3592</a>.
51         </td>
52         <td>
53 <a href="/samba/security/CVE-2022-3437.html">Announcement</a>, 
54 <a href="/samba/security/CVE-2022-3592.html">Announcement</a>.
55         </td>
56     <tr>
57
58         <td>27 July 2022</td>
59         <td><a href="/samba/ftp/patches/security/samba-4.16.4-security-2022-07-27.patch">
60         patch for Samba 4.16.4</a><br />
61         <a href="/samba/ftp/patches/security/samba-4.15.9-security-2022-07-27.patch">
62         patch for Samba 4.15.9</a><br />
63         <a href="/samba/ftp/patches/security/samba-4.14.14-security-2022-07-27.patch">
64         patch for Samba 4.14.14</a><br />
65         </td>
66         <td>CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745 and CVE-2022-32746.
67         Please see announcements for details.
68         </td>
69         <td>Please refer to the advisories.</td>
70         <td>
71 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2031">CVE-2022-2031</a>, 
72 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32742">CVE-2022-32742</a>, 
73 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32744">CVE-2022-32744</a>, 
74 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32745">CVE-2022-32745</a>, 
75 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32746">CVE-2022-32746</a>.
76         </td>
77         <td>
78 <a href="/samba/security/CVE-2022-2031.html">Announcement</a>, 
79 <a href="/samba/security/CVE-2022-32742.html">Announcement</a>, 
80 <a href="/samba/security/CVE-2022-32744.html">Announcement</a>, 
81 <a href="/samba/security/CVE-2022-32745.html">Announcement</a>, 
82 <a href="/samba/security/CVE-2022-32746.html">Announcement</a>.
83         </td>
84
85     <tr>
86         <td>31 January 2022</td>
87         <td><a href="/samba/ftp/patches/security/samba-4.15.5-security-2022-01-31.patch">
88         patch for Samba 4.15.5</a><br />
89         <a href="/samba/ftp/patches/security/samba-4.14.12-security-2022-01-31.patch">
90         patch for Samba 4.14.12</a><br />
91         <a href="/samba/ftp/patches/security/samba-4.13.17-security-2022-01-31.patch">
92         patch for Samba 4.13.17</a><br />
93         </td>
94         <td>CVE-2021-44141, CVE-2021-44142 and CVE-2022-0336. Please see announcements for details.
95         </td>
96         <td>Please refer to the advisories.</td>
97         <td>
98 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44141">CVE-2021-44141</a>, 
99 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44142">CVE-2021-44142</a>, 
100 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0336">CVE-2022-0336</a>.
101         </td>
102         <td>
103 <a href="/samba/security/CVE-2021-44141.html">Announcement</a>, 
104 <a href="/samba/security/CVE-2021-44142.html">Announcement</a>, 
105 <a href="/samba/security/CVE-2022-0336.html">Announcement</a>.
106         </td>
107
108         <tr>
109         <td>10 January 2022</td>
110         <td><a href="/samba/ftp/patches/security/samba-4.13.16-security-2022-01-10.patch">
111         patch for Samba 4.13.16</a><br />
112         </td>
113         <td>Symlink race error can allow directory creation outside of the exported share.
114         </td>
115         <td>All versions of the Samba file server prior to 4.13.16</td>
116         <td>
117         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43566">CVE-2021-43566</a>.
118         </td>
119         <td>
120         <a href="/samba/security/CVE-2021-43566.html">Announcement</a>.
121         </td>
122         </tr>
123
124     <tr>
125         <td>9 November 2021</td>
126         <td><a href="/samba/ftp/patches/security/samba-4.15.1-security-2021-11-09.patch">
127         patch for Samba 4.15.1</a><br />
128         <a href="/samba/ftp/patches/security/samba-4.14.9-security-2021-11-09.patch">
129         patch for Samba 4.14.9</a><br />
130         <a href="/samba/ftp/patches/security/samba-4.13.13-security-2021-11-09.patch">
131         patch for Samba 4.13.13</a><br />
132         </td>
133         <td>CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719,
134 CVE-2020-25721, CVE-2020-25722, CVE-2021-3738 and CVE-2021-23192. Please see announcements for details.
135         </td>
136         <td>Please refer to the advisories.</td>
137         <td>
138 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2124">CVE-2016-2124</a>, 
139 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25717">CVE-2020-25717</a>, 
140 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25718">CVE-2020-25718</a>, 
141 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25719">CVE-2020-25719</a>, 
142 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25721">CVE-2020-25721</a>, 
143 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25722">CVE-2020-25722</a>, 
144 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3738">CVE-2021-3738</a>, 
145 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23192">CVE-2021-23192</a>.
146         </td>
147         <td>
148 <a href="/samba/security/CVE-2016-2124.html">Announcement</a>, 
149 <a href="/samba/security/CVE-2020-25717.html">Announcement</a>, 
150 <a href="/samba/security/CVE-2020-25718.html">Announcement</a>, 
151 <a href="/samba/security/CVE-2020-25719.html">Announcement</a>, 
152 <a href="/samba/security/CVE-2020-25721.html">Announcement</a>, 
153 <a href="/samba/security/CVE-2020-25722.html">Announcement</a>, 
154 <a href="/samba/security/CVE-2021-3738.html">Announcement</a>, 
155 <a href="/samba/security/CVE-2021-23192.html">Announcement</a>.
156         </td>
157     </tr>
158     <tr>
159         <td>29 Apr 2021</td>
160         <td><a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
161         patch for Samba 4.14.3</a><br />
162         <a href="/samba/ftp/patches/security/samba-4.13.7-security-2021-04-29.patch">
163         patch for Samba 4.13.7</a><br />
164         <a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
165         patch for Samba 4.12.14</a><br />
166         </td>
167         <td>Negative idmap cache entries can cause incorrect group entries in
168             the Samba file server process token.
169         </td>
170         <td>All versions since 3.6.0.</td>
171         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20254">CVE-2021-20254</a>
172         </td>
173         <td><a href="/samba/security/CVE-2021-20254.html">Announcement</a>
174         </td>
175     </tr>
176
177     <tr>
178         <td>24 Mar 2021</td>
179         <td><a href="/samba/ftp/patches/security/samba-4.14.0-security-2021-03-24.patch">
180         patch for Samba 4.14.0</a><br />
181         <a href="/samba/ftp/patches/security/samba-4.13.5-security-2021-03-24.patch">
182         patch for Samba 4.13.5</a><br />
183         <a href="/samba/ftp/patches/security/samba-4.12.12-security-2021-03-24.patch">
184         patch for Samba 4.12.12</a><br />
185         </td>
186         <td>CVE-2020-27840 and CVE-2021-20277. Please see announcements for details.
187         </td>
188         <td>Please refer to the advisories.</td>
189         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27840">CVE-2020-27840</a>,
190         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20277">CVE-2021-20277</a>.
191         </td>
192         <td><a href="/samba/security/CVE-2020-27840.html">Announcement</a>,
193         <a href="/samba/security/CVE-2021-20277.html">Announcement</a>.
194         </td>
195     </tr>
196
197     <tr>
198         <td>29 Oct 2020</td>
199         <td><a href="/samba/ftp/patches/security/samba-4.13.0-security-2020-10-29.patch">
200         patch for Samba 4.13.0</a><br />
201         <a href="/samba/ftp/patches/security/samba-4.12.8-security-2020-10-29.patch">
202         patch for Samba 4.12.8</a><br />
203         <a href="/samba/ftp/patches/security/samba-4.11.14-security-2020-10-29.patch">
204         patch for Samba 4.11.14</a><br />
205         </td>
206         <td>CVE-2020-14318, CVE-2020-14323 and CVE-2020-14383. Please see announcements for details.
207         </td>
208         <td>Please refer to the advisories.</td>
209         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14318">CVE-2020-14318</a>,
210         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14323">CVE-2020-14323</a>
211         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14383">CVE-2020-14383</a>.
212         </td>
213         <td><a href="/samba/security/CVE-2020-14318.html">Announcement</a>,
214         <a href="/samba/security/CVE-2020-14323.html">Announcement</a>,
215         <a href="/samba/security/CVE-2020-14383.html">Announcement</a>.
216         </td>
217     </tr>
218
219     <tr>
220         <td>18 Sep 2020</td>
221         <td><a href="/samba/ftp/patches/security/samba-4.12.6-security-2020-09-18.patch">
222         patch for Samba 4.12.6</a><br />
223         <a href="/samba/ftp/patches/security/samba-4.11.12-security-2020-09-18.patch">
224         patch for Samba 4.11.12</a><br />
225         <a href="/samba/ftp/patches/security/samba-4.10.17-security-2020-09-18.patch">
226         patch for Samba 4.10.17</a><br />
227         </td>
228         <td>CVE-2020-1472.
229             Please see announcements for details.
230         </td>
231         <td>Please refer to the advisory.</td>
232         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1472">CVE-2020-1472</a>.
233         </td>
234         <td><a href="/samba/security/CVE-2020-1472.html">Announcement</a>,
235         </td>
236     </tr>
237
238     <tr>
239         <td>02 Jul 2020</td>
240         <td><a href="/samba/ftp/patches/security/samba-4.12.3-security-2020-07-02.patch">
241         patch for Samba 4.12.3</a><br />
242         <a href="/samba/ftp/patches/security/samba-4.11.10-security-2020-07-02.patch">
243         patch for Samba 4.11.10</a><br />
244         <a href="/samba/ftp/patches/security/samba-4.10.16-security-2020-07-02.patch">
245         patch for Samba 4.10.16</a><br />
246         </td>
247         <td>CVE-2020-10730, CVE-2020-10745, CVE-2020-10760 and CVE-2020-14303.
248             Please see announcements for details.
249         </td>
250         <td>Please refer to the advisories.</td>
251         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10730">CVE-2020-10730</a>,
252         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10745">CVE-2020-10745</a>,
253         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10760">CVE-2020-10760</a>,
254         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14303">CVE-2020-14303</a>.
255         </td>
256         <td><a href="/samba/security/CVE-2020-10730.html">Announcement</a>,
257         <a href="/samba/security/CVE-2020-10745.html">Announcement</a>,
258         <a href="/samba/security/CVE-2020-10760.html">Announcement</a>,
259         <a href="/samba/security/CVE-2020-14303.html">Announcement</a>
260         </td>
261     </tr>
262
263     <tr>
264         <td>28 Apr 2020</td>
265         <td><a href="/samba/ftp/patches/security/samba-4.12.1-security-2020-04-28.patch">
266         patch for Samba 4.12.1</a><br />
267         <a href="/samba/ftp/patches/security/samba-4.11.7-security-2020-04-28.patch">
268         patch for Samba 4.11.7</a><br />
269         <a href="/samba/ftp/patches/security/samba-4.10.14-security-2020-04-28.patch">
270         patch for Samba 4.10.14</a><br />
271         </td>
272         <td>CVE-2020-10700 and CVE-2020-10704. Please see announcements for
273         details.
274         </td>
275         <td>Please refer to the advisories.</td>
276         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10700">CVE-2020-10700</a>,
277         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10704">CVE-2020-10704</a>.
278         </td>
279         <td><a href="/samba/security/CVE-2020-10700.html">Announcement</a>,
280         <a href="/samba/security/CVE-2020-10704.html">Announcement</a>
281         </td>
282     </tr>
283
284     <tr>
285         <td>21 Jan 2020</td>
286         <td><a href="/samba/ftp/patches/security/samba-4.11.4-security-2020-01-21.patch">
287         patch for Samba 4.11.4</a><br />
288         <a href="/samba/ftp/patches/security/samba-4.10.11-security-2020-01-21.patch">
289         patch for Samba 4.10.11</a><br />
290         <a href="/samba/ftp/patches/security/samba-4.9.17-security-2020-01-21.patch">
291         patch for Samba 4.9.17</a><br />
292         </td>
293         <td>CVE-2019-14902, CVE-2019-14907 and CVE-2019-19344. Please see announcements for
294         details.
295         </td>
296         <td>Please refer to the advisories.</td>
297         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14902">CVE-2019-14902</a>,
298         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14907">CVE-2019-14907</a>,
299         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19344">CVE-2019-19344.</a>.
300         </td>
301         <td><a href="/samba/security/CVE-2019-14902.html">Announcement</a>,
302         <a href="/samba/security/CVE-2019-14907.html">Announcement</a>,
303         <a href="/samba/security/CVE-2019-19344.html">Announcement</a>
304         </td>
305     </tr>
306
307     <tr>
308         <td>10 Dec 2019</td>
309         <td><a
310 href="/samba/ftp/patches/security/samba-4.11.2-security-2019-12-10.patch">
311         patch for Samba 4.11.2</a><br />
312         <a href="/samba/ftp/patches/security/samba-4.10.10-security-2019-12-10.patch">
313         patch for Samba 4.10.10</a><br />
314         <a href="/samba/ftp/patches/security/samba-4.9.16-security-2019-12-10.patch">
315         patch for Samba 4.9.16</a><br />
316         </td>
317         <td>CVE-2019-14861 and CVE-2019-14870. Please see announcements for
318         details.
319         </td>
320         <td>All versions since Samba 4.0</td>
321         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14861">CVE-2019-14861</a>,
322         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14870">CVE-2019-14870</a>.
323         </td>
324         <td><a href="/samba/security/CVE-2019-14861.html">Announcement</a>,
325         <a href="/samba/security/CVE-2019-14870.html">Announcement</a>
326         </td>
327     </tr>
328
329     <tr>
330         <td>29 Oct 2019</td>
331         <td><a href="/samba/ftp/patches/security/samba-4.11.1-security-2019-10-29.patch">
332         patch for Samba 4.11.1</a><br />
333         <a href="/samba/ftp/patches/security/samba-4.10.9-security-2019-10-29.patch">
334         patch for Samba 4.10.9</a><br />
335         <a href="/samba/ftp/patches/security/samba-4.9.14-security-2019-10-29.patch">
336         patch for Samba 4.9.14</a><br />
337         </td>
338         <td>CVE-2019-10218, CVE-2019-14833 and CVE-2019-14847. Please see
339         announcements for details.
340         </td>
341         <td>please refer to the advisories</td>
342         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10218">CVE-2019-10218</a>,
343         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14833">CVE-2019-14833</a>,
344         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14847">CVE-2019-14847</a>
345         </td>
346         <td><a href="/samba/security/CVE-2019-10218.html">Announcement</a>,
347         <a href="/samba/security/CVE-2019-14833.html">Announcement</a>,
348         <a href="/samba/security/CVE-2019-14847.html">Announcement</a>
349         </td>
350     </tr>
351
352     <tr>
353         <td>03 Sep 2019</td>
354         <td><a href="/samba/ftp/patches/security/samba-4.10.7-CVE-2019-10197.patch">
355         patch for Samba 4.10.7</a><br />
356         <a href="/samba/ftp/patches/security/samba-4.9.12-CVE-2019-10197.patch">
357         patch for Samba 4.9.12</a><br />
358         </td>
359         <td>Combination of parameters and permissions can allow user to escape
360             from the share path definition.
361         </td>
362         <td>All versions between Samba 4.9.0 and 4.9.12/4.10.7 (incl.).</td>
363         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10197">CVE-2019-10197</a>
364         </td>
365         <td><a href="/samba/security/CVE-2019-10197.html">Announcement</a>
366         </td>
367     </tr>
368
369     <tr>
370         <td>19 Jun 2019</td>
371         <td><a href="/samba/ftp/patches/security/samba-4.10.4-security-2019-06-19.patch">
372         patch for Samba 4.10.4 (both CVEs)</a><br />
373         <a href="/samba/ftp/patches/security/samba-4.9.8-security-2019-06-19.patch">
374         patch for Samba 4.9.8 (CVE-2019-12435 only)</a><br />
375         </td>
376         <td>CVE-2019-12435 and CVE-2019-12436. Please see the announcements for details.
377         </td>
378         <td>please refer to the advisories</td>
379         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12435">CVE-2019-12435</a>,
380         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12436">CVE-2019-12436</a>
381         </td>
382         <td><a href="/samba/security/CVE-2019-12435.html">Announcement</a>,
383         <a href="/samba/security/CVE-2019-12436.html">Announcement</a>
384         </td>
385     </tr>
386
387     <tr>
388         <td>14 May 2019</td>
389         <td><a href="/samba/ftp/patches/security/samba-4.10.2-security-2019-05-14.patch">
390         patch for Samba 4.10.2</a><br />
391         <a href="/samba/ftp/patches/security/samba-4.9.7-security-2019-05-14.patch">
392         patch for Samba 4.9.7</a><br />
393         <a href="/samba/ftp/patches/security/samba-4.8.11-security-2019-05-14.patch">
394         patch for Samba 4.8.11</a><br />
395         </td>
396         <td>CVE-2018-16860. Please see the announcements for details.
397         </td>
398         <td>All versions of Samba prior to 4.10.3, 4.9.8, 4.8.12.</td>
399         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16860">CVE-2018-16860</a>
400         </td>
401         <td><a href="/samba/security/CVE-2018-16860.html">Announcement</a>
402         </td>
403     </tr>
404
405     <tr>
406         <td>08 Apr 2019</td>
407         <td><a href="/samba/ftp/patches/security/samba-4.10.1-security-2019-04-08.patch">
408         patch for Samba 4.10.1 (both CVEs)</a><br />
409         <a href="/samba/ftp/patches/security/samba-4.9.5-security-2019-04-08.patch">
410         patch for Samba 4.9.5 (both CVEs)</a><br />
411         <a href="/samba/ftp/patches/security/samba-4.8.10-security-2019-04-08.patch">
412         patch for Samba 4.8.10 (CVE-2019-3880 only)</a><br />
413         </td>
414         <td>CVE-2019-3870 and CVE-2019-3880. Please see the announcements for details.
415         </td>
416         <td>please refer to the advisories</td>
417         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3870">CVE-2019-3870</a>,
418             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3880">CVE-2019-3880</a>
419         </td>
420         <td><a href="/samba/security/CVE-2019-3870.html">Announcement</a>,
421             <a href="/samba/security/CVE-2019-3880.html">Announcement</a>
422         </td>
423     </tr>
424
425     <tr>
426         <td>27 Nov 2018</td>
427         <td><a href="/samba/ftp/patches/security/samba-4.9.2-security-2018-11-27.patch">
428         patch for Samba 4.9.2 (all CVEs)</a><br />
429         <a href="/samba/ftp/patches/security/samba-4.8.6-security-2018-11-27.patch">
430         patch for Samba 4.8.6 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
431         <a href="/samba/ftp/patches/security/samba-4.7.11-security-2018-11-27.patch">
432         patch for Samba 4.7.11 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
433         <td>Numerous CVEs. Please see the announcements for details.
434         </td>
435         <td>please refer to the advisories</td>
436         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14629">CVE-2018-14629</a>,
437             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16841">CVE-2018-16841</a>,
438             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16851">CVE-2018-16851</a>,
439             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16852">CVE-2018-16852</a>,
440             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16853">CVE-2018-16853</a>,
441             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16857">CVE-2018-16857</a>
442         </td>
443         <td><a href="/samba/security/CVE-2018-14629.html">Announcement</a>,
444             <a href="/samba/security/CVE-2018-16841.html">Announcement</a>,
445             <a href="/samba/security/CVE-2018-16851.html">Announcement</a>,
446             <a href="/samba/security/CVE-2018-16852.html">Announcement</a>,
447             <a href="/samba/security/CVE-2018-16853.html">Announcement</a>,
448             <a href="/samba/security/CVE-2018-16857.html">Announcement</a>
449         </td>
450     </tr>
451
452     <tr>
453         <td>14 Aug 2018</td>
454         <td><a href="/samba/ftp/patches/security/samba-4.8.3-security-2018-08-14.patch">
455         patch for Samba 4.8.3 (all CVEs)</a><br />
456         <a href="/samba/ftp/patches/security/samba-4.7.8-security-2018-08-14.patch">
457         patch for Samba 4.7.8 (all CVEs except CVE-2018-1140)</a><br />
458         <a href="/samba/ftp/patches/security/samba-4.6.15-security-2018-08-14.patch">
459         patch for Samba 4.6.15 (CVE-2018-10858 and CVE-2018-10919)</a><br />
460         <td>Numerous CVEs. Please see the announcements for details.
461         </td>
462         <td>please refer to the advisories</td>
463         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10858">CVE-2018-10858</a>,
464             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10918">CVE-2018-10918</a>,
465             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10919">CVE-2018-10919</a>,
466             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1139">CVE-2018-1139</a>,
467             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1140">CVE-2018-1140</a>
468         </td>
469         <td><a href="/samba/security/CVE-2018-10858.html">Announcement</a>,
470             <a href="/samba/security/CVE-2018-10918.html">Announcement</a>,
471             <a href="/samba/security/CVE-2018-10919.html">Announcement</a>,
472             <a href="/samba/security/CVE-2018-1139.html">Announcement</a>,
473             <a href="/samba/security/CVE-2018-1140.html">Announcement</a>
474         </td>
475     </tr>
476
477     <tr>
478         <td>13 Mar 2018</td>
479         <td><a href="/samba/ftp/patches/security/samba-4.7.5-security-2018-03-13.patch">
480         patch for Samba 4.7.5</a><br />
481         <a href="/samba/ftp/patches/security/samba-4.6.13-security-2018-03-13.patch">
482         patch for Samba 4.6.13</a><br />
483         <a href="/samba/ftp/patches/security/samba-4.5.15-security-2018-03-13.patch">
484         patch for Samba 4.5.15</a><br />
485         <a href="/samba/ftp/patches/security/samba-4.4.16-CVE-2018-1057.patch">
486         patch for Samba 4.4.16 (only CVE-2018-1057)</a><br />
487         <a href="/samba/ftp/patches/security/samba-4.3.13-CVE-2018-1057.patch">
488         patch for Samba 4.3.13 (only CVE-2018-1057)</a><br />
489         <td>Numerous CVEs. Please see the announcements for details.
490         </td>
491         <td>please refer to the advisories</td>
492         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1050">CVE-2018-1050</a>,
493             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1057">CVE-2018-1057</a>
494         </td>
495         <td><a href="/samba/security/CVE-2018-1050.html">Announcement</a>, 
496             <a href="/samba/security/CVE-2018-1057.html">Announcement</a>
497         </td>
498     </tr>
499
500     <tr>
501         <td>21 Nov 2017</td>
502         <td><a href="/samba/ftp/patches/security/samba-4.7.2-security-2017-11-21.patch">
503         patch for Samba 4.7.2</a><br />
504         <a href="/samba/ftp/patches/security/samba-4.6.10-security-2017-11-21.patch">
505         patch for Samba 4.6.10</a><br />
506         <a href="/samba/ftp/patches/security/samba-4.5.14-security-2017-11-21.patch">
507         patch for Samba 4.5.14</a><br />
508         <td>Numerous CVEs. Please see the announcements for details.
509         </td>
510         <td>please refer to the advisories</td>
511         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14746">CVE-2017-14746</a>, 
512             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15275">CVE-2017-15275</a>
513         </td>
514         <td><a href="/samba/security/CVE-2017-14746.html">Announcement</a>, 
515             <a href="/samba/security/CVE-2017-15275.html">Announcement</a>
516         </td>
517     </tr>
518
519     <tr>
520         <td>20 Sep 2017</td>
521         <td><a href="/samba/ftp/patches/security/samba-4.6.7-security-2017-09-20.patch">
522         patch for Samba 4.6.7</a><br />
523         <a href="/samba/ftp/patches/security/samba-4.5.13-security-2017-09-20.patch">
524         patch for Samba 4.5.13</a><br />
525         <a href="/samba/ftp/patches/security/samba-4.4.15-security-2017-09-20.patch">
526         patch for Samba 4.4.15</a><br />
527         <td>Numerous CVEs. Please see the announcements for details.
528         </td>
529         <td>please refer to the advisories</td>
530         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12150">CVE-2017-12150</a>, 
531             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12151">CVE-2017-12151</a>, 
532             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12163">CVE-2017-12163</a>
533         </td>
534         <td><a href="/samba/security/CVE-2017-12150.html">Announcement</a>, 
535             <a href="/samba/security/CVE-2017-12151.html">Announcement</a>, 
536             <a href="/samba/security/CVE-2017-12163.html">Announcement</a>
537         </td>
538     </tr>
539
540     <tr>
541         <td>12 July 2017</td>
542         <td><a href="/samba/ftp/patches/security/samba-4.x.y-CVE-2017-11103.patch">
543         patch for Samba 4.x.y</a><br />
544         <td>Orpheus&apos; Lyre mutual authentication validation bypass.
545         </td>
546         <td>All versions between Samba 4.0.0 and 4.6.6/4.5.12/4.4.15</td>
547         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11103">CVE-2017-11103</a>
548         </td>
549         <td><a href="/samba/security/CVE-2017-11103.html">Announcement</a>
550         </td>
551     </tr>
552
553     <tr>
554         <td>24 May 2017</td>
555         <td><a href="/samba/ftp/patches/security/samba-4.6.3-4.5.9-4.4.13-CVE-2017-7494.patch">
556         patch for Samba 4.6.3, 4.5.9, 4.4.13</a><br />
557         <td>Remote code execution from a writable share.
558         </td>
559         <td>All versions between Samba 3.5.0 and 4.6.4/4.5.10/4.4.14</td>
560         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7494">CVE-2017-7494</a>
561         </td>
562         <td><a href="/samba/security/CVE-2017-7494.html">Announcement</a>
563         </td>
564     </tr>
565
566     <tr>
567         <td>23 Mar 2017</td>
568         <td><a href="/samba/ftp/patches/security/samba-4.6.0-CVE-2017-2619.patch">
569         patch for Samba 4.6.0</a><br />
570         <a href="/samba/ftp/patches/security/samba-4.5.6-CVE-2017-2619.patch">
571         patch for Samba 4.5.6</a><br />
572         <a href="/samba/ftp/patches/security/samba-4.4.11-CVE-2017-2619.patch">
573         patch for Samba 4.4.11</a><br />
574         <td>Symlink race allows access outside share definition.
575         </td>
576         <td>All versions of Samba prior to 4.6.1, 4.5.7, 4.4.12</td>
577         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2619">CVE-2017-2619</a>
578         </td>
579         <td><a href="/samba/security/CVE-2017-2619.html">Announcement</a>
580         </td>
581     </tr>
582
583     <tr>
584         <td>19 Dec 2016</td>
585         <td><a href="/samba/ftp/patches/security/samba-4.5.2-security-20016-12-19.patch">
586         patch for Samba 4.5.2</a><br />
587         <a href="/samba/ftp/patches/security/samba-4.4.7-security-20016-12-19.patch">
588         patch for Samba 4.4.7</a><br />
589         <a href="/samba/ftp/patches/security/samba-4.3.12-security-20016-12-19.patch">
590         patch for Samba 4.3.12</a><br />
591         <td>Numerous CVEs. Please see the announcements for details.
592         </td>
593         <td>please refer to the advisories</td>
594         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2123">CVE-2016-2123</a>, 
595             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2125">CVE-2016-2125</a>, 
596             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2126">CVE-2016-2126</a>
597         </td>
598         <td><a href="/samba/security/CVE-2016-2123.html">Announcement</a>, 
599             <a href="/samba/security/CVE-2016-2125.html">Announcement</a>, 
600             <a href="/samba/security/CVE-2016-2126.html">Announcement</a>
601         </td>
602     </tr>
603
604     <tr>
605         <td>07 Jul 2016</td>
606         <td><a href="/samba/ftp/patches/security/samba-4.4.4-CVE-2016-2119.patch">
607         patch for Samba 4.4.4</a><br />
608         <a href="/samba/ftp/patches/security/samba-4.3.10-CVE-2016-2119.patch">
609         patch for Samba 4.3.10</a><br />
610         <a href="/samba/ftp/patches/security/samba-4.2.13-CVE-2016-2119.patch">
611         patch for Samba 4.2.13</a><br />
612         <td>Client side SMB2/3 required signing can be downgraded.
613         </td>
614         <td>4.0.0 - 4.4.4</td>
615         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2119">CVE-2016-2119</a>
616         </td>
617         <td><a href="/samba/security/CVE-2016-2119.html">Announcement</a>
618         </td>
619     </tr>
620
621     <tr>
622         <td>12 Apr 2016</td>
623         <td><a href="/samba/ftp/patches/security/samba-4.4.0-security-2016-04-12-final.patch">
624         patch for Samba 4.4.0</a><br />
625         <a href="/samba/ftp/patches/security/samba-4.3.6-security-2016-04-12-final.patch">
626         patch for Samba 4.3.6</a><br />
627         <a href="/samba/ftp/patches/security/samba-4.2.9-security-2016-04-12-final.patch">
628         patch for Samba 4.2.9</a><br />
629         <a href="/samba/ftp/patches/security/samba-v4-0-security-2016-04-12-fileserver-only.patch.xz">
630         patch for Samba 4.0.26 (fileserver only! no client! no domain controller!)</a><br />
631         <a href="/samba/ftp/patches/security/samba-v3-6-security-2016-04-12.tar.xz">
632         patch for Samba 3.6.25 (only related CVEs)</a><br />
633         <td>Numerous CVEs. Please see the announcements for details.
634         </td>
635         <td>please refer to the advisories</td>
636         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5370">CVE-2015-5370</a>, 
637             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2110">CVE-2016-2110</a>, 
638             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2111">CVE-2016-2111</a>, 
639             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2112">CVE-2016-2112</a>, 
640             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2113">CVE-2016-2113</a>, 
641             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2114">CVE-2016-2114</a>, 
642             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2115">CVE-2016-2115</a>, 
643             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2118">CVE-2016-2118</a>
644         </td>
645         <td><a href="/samba/security/CVE-2015-5370.html">Announcement</a>
646             <a href="/samba/security/CVE-2016-2110.html">Announcement</a>
647             <a href="/samba/security/CVE-2016-2111.html">Announcement</a>
648             <a href="/samba/security/CVE-2016-2112.html">Announcement</a>
649             <a href="/samba/security/CVE-2016-2113.html">Announcement</a>
650             <a href="/samba/security/CVE-2016-2114.html">Announcement</a>
651             <a href="/samba/security/CVE-2016-2115.html">Announcement</a>
652             <a href="/samba/security/CVE-2016-2118.html">Announcement</a>
653         </td>
654     </tr>
655
656     <tr>
657         <td>08 Mar 2016</td>
658         <td><a href="/samba/ftp/patches/security/samba-4.3.5-security-2016-03-08.patch">
659         patch for Samba 4.3.5</a><br />
660         <a href="/samba/ftp/patches/security/samba-4.2.8-security-2016-03-08.patch">
661         patch for Samba 4.2.8</a><br />
662         <a href="/samba/ftp/patches/security/samba-4.1.22-security-2016-03-08.patch">
663         patch for Samba 4.1.22</a><br />
664         <td>Incorrect ACL get/set allowed on symlink path, Out-of-bounds read in internal DNS server.
665         </td>
666         <td>please refer to the advisories</td>
667         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7560">CVE-2015-7560</a>, 
668             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0771">CVE-2016-0771</a>, 
669         </td>
670         <td><a href="/samba/security/CVE-2015-7560.html">Announcement</a>
671             <a href="/samba/security/CVE-2016-0771.html">Announcement</a>
672         </td>
673     </tr>
674
675     <tr>
676         <td>16 Dec 2015</td>
677         <td><a href="/samba/ftp/patches/security/samba-4.3.2-security-2015-12-16.patch">
678         patch for Samba 4.3.2</a><br />
679         <a href="/samba/ftp/patches/security/samba-4.2.6-security-2015-12-16.patch">
680         patch for Samba 4.2.6</a><br />
681         <a href="/samba/ftp/patches/security/samba-4.1.21-security-2015-12-16.patch">
682         patch for Samba 4.1.21</a><br />
683         <a href="/samba/ftp/patches/security/samba-3.6.25-security-2015-12-16.patch">
684         patch for Samba 3.6.25</a><br />
685         <td>Numerous CVEs. Please see the announcements for details.
686         </td>
687         <td>3.0.0 to 4.3.2</td>
688         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3223">CVE-2015-3223</a>, 
689             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5252">CVE-2015-5252</a>, 
690             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5296">CVE-2015-5296</a>, 
691             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5299">CVE-2015-5299</a>, 
692             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5330">CVE-2015-5330</a>, 
693             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7540">CVE-2015-7540</a>, 
694             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8467">CVE-2015-8467</a>
695         </td>
696         <td><a href="/samba/security/CVE-2015-3223.html">Announcement</a>
697             <a href="/samba/security/CVE-2015-5252.html">Announcement</a>
698             <a href="/samba/security/CVE-2015-5296.html">Announcement</a>
699             <a href="/samba/security/CVE-2015-5299.html">Announcement</a>
700             <a href="/samba/security/CVE-2015-5330.html">Announcement</a>
701             <a href="/samba/security/CVE-2015-7540.html">Announcement</a>
702             <a href="/samba/security/CVE-2015-8467.html">Announcement</a>
703         </td>
704     </tr>
705
706     <tr>
707         <td>23 Feb 2015</td>
708         <td><a href="/samba/ftp/patches/security/samba-4.1.16-CVE-2015-0240.patch">
709         patch for Samba 4.1.16</a><br />
710         <a href="/samba/ftp/patches/security/samba-4.0.24-CVE-2015-0240.patch">
711         patch for Samba 4.0.24</a><br />
712         <a href="/samba/ftp/patches/security/samba-3.6.24-CVE-2015-0240.patch">
713         patch for Samba 3.6.24</a><br />
714         <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2015-0240.patch">
715         patch for Samba 3.5.22</a><br />
716         <td>Unexpected code execution in smbd.
717         </td>
718         <td>3.5.0 - 4.2.0rc4</td>
719         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0240">CVE-2015-0240</a>
720         </td>
721         <td><a href="/samba/security/CVE-2015-0240.html">Announcement</a>
722         </td>
723     </tr>
724
725     <tr>
726         <td>15 Jan 2015</td>
727         <td><a href="/samba/ftp/patches/security/samba-4.1.15-CVE-2014-8143.patch">
728         patch for Samba 4.1.15</a><br />
729         <a href="/samba/ftp/patches/security/samba-4.0.23-CVE-2014-8143.patch">
730         patch for Samba 4.0.23</a><br />
731         <td>Elevation of privilege to Active Directory Domain Controller.
732         </td>
733         <td>4.0.0 - 4.1.15</td>
734         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8143">CVE-2014-8143</a>
735         </td>
736         <td><a href="/samba/security/CVE-2014-8143.html">Announcement</a>
737         </td>
738     </tr>
739
740     <tr>
741         <td>01 Aug 2014</td>
742         <td><a href="/samba/ftp/patches/security/samba-4.1.10-CVE-2014-3560.patch">
743         patch for Samba 4.1.10</a><br />
744         <a href="/samba/ftp/patches/security/samba-4.0.20-CVE-2014-3560.patch">
745         patch for Samba 4.0.20</a><br />
746         <td>Remote code execution in nmbd.
747         </td>
748         <td>4.0.0 - 4.1.10</td>
749         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3560">CVE-2014-3560</a>
750         </td>
751         <td><a href="/samba/security/CVE-2014-3560.html">Announcement</a>
752         </td>
753     </tr>
754
755     <tr>
756         <td>23 Jun 2014</td>
757         <td><a href="/samba/ftp/patches/security/samba-4.1.8-CVE-2014-0244-CVE-2014-3493.patch">
758         patch for Samba 4.1.8</a><br />
759         <a href="/samba/ftp/patches/security/samba-4.0.18-CVE-2014-0244-CVE-2014-3493.patch">
760         patch for Samba 4.0.18</a><br />
761         <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0244-CVE-2014-3493.patch">
762         patch for Samba 3.6.23</a><br />
763         <td>Denial of service - CPU loop, Denial of service - Server crash/memory corruption.
764         </td>
765         <td>please refer to the advisories</td>
766         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0244">CVE-2014-0244</a>, 
767             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3493">CVE-2014-3493</a>
768         </td>
769         <td><a href="/samba/security/CVE-2014-0244.html">Announcement</a>
770             <a href="/samba/security/CVE-2014-3493.html">Announcement</a>
771         </td>
772     </tr>
773
774     <tr>
775         <td>03 June 2014</td>
776         <td><a href="/samba/ftp/patches/security/samba-4.0.17-CVE-2014-0178-CVE-2014-0239.patch">
777         patch for Samba 4.0.17</a><br />
778         <a href="/samba/ftp/patches/security/samba-4.1.7-CVE-2014-0178-CVE-2014-0239.patch">
779         patch for Samba 4.1.7</a><br />
780         <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0178.patch">
781         patch for Samba 3.6.23 (CVE-2014-0178 only)</a><br />
782         <td>Uninitialized memory exposure, Potential DOS in Samba internal DNS server.
783         </td>
784         <td>please refer to the advisories</td>
785         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0178">CVE-2014-0178</a>, 
786             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0239">CVE-2014-0239</a>
787         </td>
788         <td><a href="/samba/security/CVE-2014-0178.html">Announcement</a>
789             <a href="/samba/security/CVE-2014-0239.html">Announcement</a>
790         </td>
791     </tr>
792
793     <tr>
794         <td>11 Mar 2014</td>
795         <td><a href="/samba/ftp/patches/security/samba-4.1.5-CVE-2013-4496-CVE-2013-6442.patch">
796         patch for Samba 4.1.5</a><br />
797         <a href="/samba/ftp/patches/security/samba-4.0.15-CVE-2013-4496-CVE-2013-6442.patch">
798         patch for Samba 4.0.15</a><br />
799         <a href="/samba/ftp/patches/security/samba-3.6.22-CVE-2013-4496.patch">
800         patch for Samba 3.6.22</a><br />
801         <td>Password lockout not enforced for SAMR password changes, smbcacls can remove a file
802         or directory ACL by mistake.
803         </td>
804         <td>please refer to the advisories</td>
805         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496">CVE-2013-4496</a>, 
806             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6442">CVE-2013-6442</a>
807         </td>
808         <td><a href="/samba/security/CVE-2013-4496.html">Announcement</a>
809             <a href="/samba/security/CVE-2013-6442.html">Announcement</a>
810         </td>
811     </tr>
812
813     <tr>
814         <td>09 Dec 2013</td>
815         <td><a href="/samba/ftp/patches/security/samba-4.1.2-CVE-2013-4408-CVE-2012-6150.patch">
816         patch for Samba 4.1.2</a><br />
817         <a href="/samba/ftp/patches/security/samba-4.0.12-CVE-2013-4408-CVE-2012-6150.patch">
818         patch for Samba 4.0.12</a><br />
819         <a href="/samba/ftp/patches/security/samba-3.6.21-CVE-2013-4408-CVE-2012-6150.patch">
820         patch for Samba 3.6.21</a><br />
821         <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2013-4408.patch">
822         patch for Samba 3.5.22</a><br />
823         <a href="/samba/ftp/patches/security/samba-3.4.17-CVE-2013-4408.patch">
824         patch for Samba 3.4.17</a>
825         <td>DCE-RPC fragment length field is incorrectly checked, pam_winbind
826         login without require_membership_of restrictions.</td>
827         <td>please refer to the advisories</td>
828         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408">CVE-2013-4408</a>, 
829             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150">CVE-2012-6150</a>
830         </td>
831         <td><a href="/samba/security/CVE-2013-4408.html">Announcement</a>
832             <a href="/samba/security/CVE-2012-6150.html">Announcement</a>
833         </td>
834     </tr>
835
836     <tr>
837         <td>11 Nov 2013</td>
838         <td><a href="/samba/ftp/patches/security/samba-4.1.0-CVE-2013-4475-CVE-2013-4476.patch">
839         patch for Samba 4.1.0</a><br />
840         <a href="/samba/ftp/patches/security/samba-4.0.10-CVE-2013-4475-CVE-2013-4476.patch">
841         patch for Samba 4.0.10</a><br />
842         <a href="/samba/ftp/patches/security/samba-3.6.19-CVE-2013-4475.patch">
843         patch for Samba 3.6.19</a><br />
844         <td>ACLs are not checked on opening an alternate data stream on a file
845             or directory, Private key in key.pem world readable.</td>
846         <td>3.2.0 - 4.1.0, 4.0.0 - 4.0.10, 4.1.0</td>
847         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475">CVE-2013-4475</a>, 
848             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4476">CVE-2013-4476</a>
849         </td>
850         <td><a href="/samba/security/CVE-2013-4475.html">Announcement</a>
851             <a href="/samba/security/CVE-2013-4476.html">Announcement</a>
852         </td>
853     </tr>
854
855     <tr>
856         <td>05 Aug 2013</td>
857         <td><a href="/samba/ftp/patches/security/samba-4.0.7-CVE-2013-4124.patch">
858         patch for Samba 4.0.7</a><br />
859         <a href="/samba/ftp/patches/security/samba-3.6.16-CVE-2013-4124.patch">
860         patch for Samba 3.6.16</a><br />
861         <a href="/samba/ftp/patches/security/samba-3.5.21-CVE-2013-4124.patch">
862         patch for Samba 3.5.21</a><br />
863         <td>Denial of service - CPU loop and memory allocation.</td>
864         <td>3.0.x-4.0.7</td>
865         <td><a
866         href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124">CVE-2013-4124</a>
867         </td>
868         <td><a href="/samba/security/CVE-2013-4124.html">Announcement</a>
869         </td>
870     </tr>
871
872     <tr>
873         <td>02 Apr 2013</td>
874         <td><a href="/samba/ftp/patches/security/samba-3.6-CVE-2013-0454.patch">
875         patch for Samba 3.6.5</a>
876         <td>A writable configured share might get read only</td>
877         <td>3.6.0 - 3.6.5 (inclusive)</td>
878         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0454">CVE-2013-0454</a>
879         </td>
880         <td><a href="/samba/security/CVE-2013-0454.html">Announcement</a>
881         </td>
882     </tr>
883
884     <tr>
885         <td>19 Mar 2013</td>
886         <td><a href="/samba/ftp/patches/security/samba-4.0.3-CVE-2013-1863.patch">
887         patch for Samba 4.0.3</a>
888         <td>World-writeable files may be created in additional shares on a Samba
889         4.0 AD DC.</td>
890         <td>4.0.0rc6-4.0.3</td>
891         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1863">CVE-2013-1863</a>
892         </td>
893         <td><a href="/samba/security/CVE-2013-1863.html">Announcement</a>
894         </td>
895     </tr>
896
897     <tr>
898         <td>30 Jan 2013</td>
899         <td><a href="/samba/ftp/patches/security/samba-4.0.1-CVE-2013-0213-CVE-2013-0214.patch">
900         patch for Samba 4.0.1</a><br />
901         <a href="/samba/ftp/patches/security/samba-3.6.11-CVE-2013-0213-CVE-2013-0214.patch">
902         patch for Samba 3.6.11</a><br />
903         <a href="/samba/ftp/patches/security/samba-3.5.20-CVE-2013-0213-CVE-2013-0214.patch">
904         patch for Samba 3.5.20</a><br />
905         <td>Clickjacking issue and potential XSRF in SWAT.</td>
906         <td>3.0.x-4.0.1</td>
907         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213">CVE-2013-0213</a>, 
908             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214">CVE-2013-0214</a>
909         </td>
910         <td><a href="/samba/security/CVE-2013-0213.html">Announcement</a>
911             <a href="/samba/security/CVE-2013-0214.html">Announcement</a>
912         </td>
913     </tr>
914
915     <tr>
916         <td>15 Jan 2013</td>
917         <td><a href="/samba/ftp/patches/security/samba-4.0.0-CVE-2013-0172.patch">
918         patch for Samba 4.0.0</a>
919         <td>Samba 4.0 as an AD DC may provide authenticated users with write
920         access to LDAP directory objects.</td>
921         <td>4.0.0</td>
922         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0172">CVE-2013-0172</a></td>
923         <td><a href="/samba/security/CVE-2013-0172.html">Announcement</a></td>
924     </tr>
925
926     <tr>
927         <td>30 Apr 2012</td>
928         <td><a href="/samba/ftp/patches/security/samba-3.4.16-CVE-2012-2111.patch">
929         patch for Samba 3.4.16</a><br />
930         <a href="/samba/ftp/patches/security/samba-3.5.14-CVE-2012-2111.patch">
931         patch for Samba 3.5.14</a><br />
932         <a href="/samba/ftp/patches/security/samba-3.6.4-CVE-2012-2111.patch">
933         patch for Samba 3.6.4</a><br />
934         <td>Incorrect permission checks when granting/removing privileges can
935         compromise file server security.</td>
936         <td>3.4.x-3.6.4</td>
937         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2111">CVE-2012-2111</a></td>
938         <td><a href="/samba/security/CVE-2012-2111.html">Announcement</a></td>
939     </tr>
940
941     <tr>
942         <td>10 Apr 2012</td>
943         <td><a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2012-1182.patch">
944         patch for Samba 3.0.37</a><br />
945         <a href="/samba/ftp/patches/security/samba-3.2.15-CVE-2012-1182.patch">
946         patch for Samba 3.2.15</a><br />
947         <a href="/samba/ftp/patches/security/samba-3.3.16-CVE-2012-1182.patch">
948         patch for Samba 3.3.16</a><br />
949         <a href="/samba/ftp/patches/security/samba-3.4.15-CVE-2012-1182.patch">
950         patch for Samba 3.4.15</a><br />
951         <a href="/samba/ftp/patches/security/samba-3.5.13-CVE-2012-1182.patch">
952         patch for Samba 3.5.13</a><br />
953         <a href="/samba/ftp/patches/security/samba-3.6.3-CVE-2012-1182.patch">
954         patch for Samba 3.6.3</a><br />
955         <td>"root" credential remote code execution</td>
956         <td>all current releases</td>
957         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182">CVE-2012-1182</a></td>
958         <td><a href="/samba/security/CVE-2012-1182.html">Announcement</a></td>
959     </tr>
960
961     <tr>
962         <td>23 Feb 2012</td>
963         <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2012-0870.patch">
964         patch for Samba 3.0</a><br />
965         <a href="/samba/ftp/patches/security/samba-3.2-CVE-2012-0870.patch">
966         patch for Samba 3.2</a><br />
967         <a href="/samba/ftp/patches/security/samba-3.3-CVE-2012-0870.patch">
968         patch for Samba 3.3</a><br />
969         <td>Remote code execution vulnerability in smbd</td>
970         <td>pre-3.4</td>
971         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0870">CVE-2012-0870</a></td>
972         <td><a href="/samba/security/CVE-2012-0870.html">Announcement</a></td>
973     </tr>
974
975     <tr>
976         <td>29 Jan 2012</td>
977         <td><a href="/samba/ftp/patches/security/samba-3.6.2-CVE-2012-0817.patch">
978         patch for Samba 3.6.2</a>
979         <td>Memory leak/Denial of service</td>
980         <td>3.6.0-3.6.2</td>
981         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0817">CVE-2012-0817</a></td>
982         <td><a href="/samba/security/CVE-2012-0817.html">Announcement</a></td>
983     </tr>
984
985     <tr>
986         <td>26 Jul 2011</td>
987         <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2522.patch">
988         patch for Samba 3.3.15</a><br />
989         <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2522.patch">
990         patch for Samba 3.4.13</a><br />
991         <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2522.patch">
992         patch for Samba 3.5.9</a><br />
993         <td>Cross-Site Request Forgery in SWAT</td>
994         <td>all current releases</td>
995         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2522">CVE-2011-2522</a></td>
996         <td><a href="/samba/security/CVE-2011-2522.html">Announcement</a></td>
997     </tr>
998
999     <tr>
1000         <td>26 Jul 2011</td>
1001         <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2694.patch">
1002         patch for Samba 3.3.15</a><br />
1003         <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2694.patch">
1004         patch for Samba 3.4.13</a><br />
1005         <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2694.patch">
1006         patch for Samba 3.5.9</a><br />
1007         <td>Cross-Site Scripting vulnerability in SWAT</td>
1008         <td>all current releases</td>
1009         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2694">CVE-2011-2694</a></td>
1010         <td><a href="/samba/security/CVE-2011-2694.html">Announcement</a></td>
1011     </tr>
1012
1013     <tr>
1014         <td>18 Feb 2011</td>
1015         <td><a href="/samba/ftp/patches/security/samba-3.3.14-CVE-2011-0719.patch">
1016         patch for Samba 3.3.14</a><br />
1017         <a href="/samba/ftp/patches/security/samba-3.4.11-CVE-2011-0719.patch">
1018         patch for Samba 3.4.11</a><br />
1019         <a href="/samba/ftp/patches/security/samba-3.5.6-CVE-2011-0719.patch">
1020         patch for Samba 3.5.6</a><br />
1021         <td>Denial of service - memory corruption</td>
1022         <td>all current releases</td>
1023         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0719">CVE-2011-0719</a></td>
1024         <td><a href="/samba/security/CVE-2011-0719.html">Announcement</a></td>
1025     </tr>
1026
1027     <tr>
1028         <td>14 Sep 2010</td>
1029         <td><a href="/samba/ftp/patches/security/samba-3.3.13-CVE-2010-3069.patch">
1030         patch for Samba 3.3.13</a><br />
1031         <a href="/samba/ftp/patches/security/samba-3.4.8-CVE-2010-3069.patch">
1032         patch for Samba 3.4.8</a><br />
1033         <a href="/samba/ftp/patches/security/samba-3.5.4-CVE-2010-3069.patch">
1034         patch for Samba 3.5.4</a><br />
1035         <td>Buffer Overrun Vulnerability</td>
1036         <td>all current releases</td>
1037         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3069">CVE-2010-3069</a></td>
1038         <td><a href="/samba/security/CVE-2010-3069.html">Announcement</a></td>
1039     </tr>
1040
1041     <tr>
1042         <td>16 Jun 2010</td>
1043         <td><a href="/samba/ftp/patches/security/samba-3.3.12-CVE-2010-2063.patch">
1044         patch for Samba 3.3.12 and 3.2.15</a><br />
1045         <a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2010-2063.patch">
1046         patch for Samba 3.0.37</a><br />
1047         <td>Memory Corruption Vulnerability</td>
1048         <td>3.0.x, 3.2.x, 3.3.0-3.3.12</td>
1049         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-CVE-2010-2063">CVE-2010-2063</a></td>
1050         <td><a href="/samba/security/CVE-2010-2063.html">Announcement</a></td>
1051     </tr>
1052
1053     <tr>
1054         <td>08 Mar 2010</td>
1055         <td><a href="/samba/ftp/patches/security/samba-3.5.0-CVE-2010-0728.patch">
1056         patch for Samba 3.5.0</a><br />
1057         <a href="/samba/ftp/patches/security/samba-3.4.6-CVE-2010-0728.patch">
1058         patch for Samba 3.4.6</a><br />
1059         <a href="/samba/ftp/patches/security/samba-3.3.11-CVE-2010-0728.patch">
1060         patch for Samba 3.3.11</a><br />
1061         <td>Permission ignored</td>
1062         <td>3.3.11, 3.4.6, 3.5.0</td>
1063         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0728">CVE-2010-0728</a></td>
1064         <td><a href="/samba/security/CVE-2010-0728.html">Announcement</a></td>
1065     </tr>
1066
1067     <tr>
1068         <td>02 Feb 2010</td>
1069                   <td>not available</td>
1070         <td>Change parameter "wide links" to default to "no"</td>
1071         <td>pre-3.4.6</td>
1072         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926">CVE-2010-0926</a></td>
1073         <td><a href="/samba/security/CVE-2010-0926.html">Announcement</a></td>
1074     </tr>
1075
1076     <tr>
1077         <td>01 Oct 2009</td>
1078         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-1.patch">
1079         patch 1 for Samba 3.4.1</a>
1080         <a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-2.patch">
1081         patch 2 for Samba 3.4.1</a>
1082         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-1.patch">
1083         patch 1 for Samba 3.3.7</a>
1084         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-2.patch">
1085         patch 2 for Samba 3.3.7</a>
1086         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-1.patch">
1087         patch 1 for Samba 3.2.14</a>
1088         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-2.patch">
1089         patch 2 for Samba 3.2.14</a>
1090         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-1.patch">
1091         patch 1 for Samba 3.0.36</a>
1092         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-2.patch">
1093         patch 2 for Samba 3.0.36</a>
1094         <td>Information disclosure by setuid mount.cifs</td>
1095         <td>all releases</td>
1096         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2948</a></td>
1097         <td><a href="/samba/security/CVE-2009-2948.html">Announcement</a></td>
1098     </tr>
1099
1100     <tr>
1101         <td>01 Oct 2009</td>
1102         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2906.patch">
1103         patch for Samba 3.4.1</a><br />
1104         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2906.patch">
1105         patch for Samba 3.3.7</a><br />
1106         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2906.patch">
1107         patch for Samba 3.2.14</a><br />
1108         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2906.patch">
1109         patch for Samba 3.0.36</a><br />
1110         <td>Remote DoS against smbd on authenticated connections</td>
1111         <td>all releases</td>
1112         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2906</a></td>
1113         <td><a href="/samba/security/CVE-2009-2906.html">Announcement</a></td>
1114     </tr>
1115     <tr>
1116
1117     <tr>
1118         <td>01 Oct 2009</td>
1119         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2813.patch">
1120         patch for Samba 3.4.1</a><br />
1121         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2813.patch">
1122         patch for Samba 3.3.7</a><br />
1123         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2813.patch">
1124         patch for Samba 3.2.14</a><br />
1125         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2813.patch">
1126         patch for Samba 3.0.36</a><br />
1127         <td>Misconfigured /etc/passwd file may share folders unexpectedly</td>
1128         <td>&gt; 3.0.11</td>
1129         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813">CVE-2009-2813</a></td>
1130         <td><a href="/samba/security/CVE-2009-2813.html">Announcement</a></td>
1131     </tr>
1132     <tr>
1133
1134     <tr>
1135         <td>23 Jun 2009</td>
1136         <td><a href="/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patch">
1137         patch for Samba 3.3.5</a><br />
1138         <a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patch">
1139         patch for Samba 3.2.12</a><br />
1140         <a href="/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patch">
1141         patch for Samba 3.0.34</a><br />
1142         <td>Uninitialized read of a data value</td>
1143         <td>Samba 3.0.31 - 3.3.5</td>
1144         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888">CVE-2009-1888</a></td>
1145         <td><a href="/samba/security/CVE-2009-1888.html">Announcement</a></td>
1146     </tr>
1147     <tr>
1148
1149     <tr>
1150         <td>23 Jun 2009</td>
1151         <td><a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1886.patch">
1152         patch for Samba 3.2.12</a>
1153         <td>Formatstring vulnerability in smbclient</td>
1154         <td>Samba 3.2.0 - 3.2.12</td>
1155         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886">CVE-2009-1886</a></td>
1156         <td><a href="/samba/security/CVE-2009-1886.html">Announcement</a></td>
1157     </tr>
1158     <tr>
1159
1160     <tr>
1161         <td>05 Jan 2009</td>
1162         <td><a href="/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch">
1163         patch for Samba 3.2.6</a>
1164         <td>Potential access to "/" in setups with registry shares enabled</td>
1165         <td>Samba 3.2.0 - 3.2.6</td>
1166         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0022">CVE-2009-0022</a></td>
1167         <td><a href="/samba/security/CVE-2009-0022.html">Announcement</a></td>
1168     </tr>
1169     <tr>
1170         <td>27 Nov 2008</td>
1171         <td><a href="/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patch">
1172         patch for Samba 3.0.32</a>
1173         <a href="/samba/ftp/patches/security/samba-3.2.4-CVE-2008-4314.patch">
1174         patch for Samba 3.2.4</a></td>
1175         <td>Potential leak of arbitrary memory contents</td>
1176         <td>Samba 3.0.29 - 3.2.4</td>
1177         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4314">CVE-2008-4314</a></td>
1178         <td><a href="/samba/security/CVE-2008-4314.html">Announcement</a></td>
1179     </tr>
1180
1181     <tr>
1182         <td>27 Aug 2008</td>
1183         <td><a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-1.patch">
1184         patch 1 for Samba 3.2.2</a> 
1185         <a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-2.patch">
1186         patch 2 for Samba 3.2.2</a></td>
1187         <td>Wrong permissions of group_mapping.ldb</td>
1188         <td>Samba 3.2.0 - 3.2.2</td>
1189         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3789">CVE-2008-3789</a></td>
1190         <td><a href="/samba/security/CVE-2008-3789.html">Announcement</a></td>
1191     </tr>
1192
1193     <tr>
1194         <td>29 May 2008</td>
1195         <td><a href="/samba/ftp/patches/security/samba-3.0.29-CVE-2008-1105.patch">patch for Samba 3.0.29</a></td>
1196         <td>Boundary failure when parsing SMB responses</td>
1197         <td>Samba 3.0.0 - 3.0.29</td>
1198         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105">CVE-2008-1105</a></td>
1199         <td><a href="/samba/security/CVE-2008-1105.html">Announcement</a></td>
1200     </tr>
1201
1202     <tr>
1203         <td>10 Dec 2007</td>
1204         <td><a href="/samba/ftp/patches/security/samba-3.0.27a-CVE-2007-6015.patch">patch for Samba 3.0.27a</a></td>
1205         <td>Remote Code Execution in Samba's nmbd (send_mailslot())</td>
1206         <td>Samba 3.0.0 - 3.0.27a</td>
1207         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6015">CVE-2007-6015</a></td>
1208         <td><a href="/samba/security/CVE-2007-6015.html">Announcement</a></td>
1209     </tr>
1210
1211     <tr>
1212         <td>15 Nov 2007</td>
1213         <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-5398.patch">patch for Samba 3.0.26a</a></td>
1214         <td>Remote Code Execution in Samba's nmbd</td>
1215         <td>Samba 3.0.0 - 3.0.26a</td>
1216         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398">CVE-2007-5398</a></td>
1217         <td><a href="/samba/security/CVE-2007-5398.html">Announcement</a></td>
1218     </tr>
1219
1220     <tr>
1221         <td>15 Nov 2007</td>
1222         <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-4572.patch">patch for Samba 3.0.26a</a></td>
1223         <td>GETDC mailslot processing buffer overrun in nmbd</td>
1224         <td>Samba 3.0.0 - 3.0.26a</td>
1225         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4572">CVE-2007-4572</a></td>
1226         <td><a href="/samba/security/CVE-2007-4572.html">Announcement</a></td>
1227     </tr>
1228
1229     <tr>
1230         <td>11 Sep 2007</td>
1231         <td><a href="/samba/ftp/patches/security/samba-3.0.25-CVE-2007-4138.patch">patch for Samba 3.0.25</a></td>
1232         <td>Incorrect primary group assignment for users using the rfc2307 or sfu nss info plugin.</td>
1233         <td>Samba 3.0.25 - 3.0.25c</td>
1234         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4138">CVE-2007-4138</a></td>
1235         <td><a href="/samba/security/CVE-2007-4138.html">Announcement</a></td>
1236     </tr>
1237
1238     <tr>
1239         <td>14 May 2007</td>
1240         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2447_v2.patch">patch for Samba 3.0.24</a></td>
1241         <td>Remote Command Injection Vulnerability (Updated June 5 to include missing &quot;c&quot; character from INCLUDE list).</td>
1242         <td>Samba 3.0.0 - 3.0.25rc3</td>
1243         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2447">CVE-2007-2447</a></td>
1244         <td><a href="/samba/security/CVE-2007-2447.html">Announcement</a></td>
1245     </tr>
1246
1247     <tr>
1248         <td>14 May 2007</td>
1249         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2446_v2.patch">patch for Samba 3.0.24</a></td>
1250         <td>Multiple Heap Overflows Allow Remote Code Execution (Updated May 25 to fix regression in Samba domain controller logon code).</td>
1251         <td>Samba 3.0.0 - 3.0.25rc3</td>
1252         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2446">CVE-2007-2446</a></td>
1253         <td><a href="/samba/security/CVE-2007-2446.html">Announcement</a></td>
1254     </tr>
1255
1256     <tr>
1257         <td>14 May 2007</td>
1258         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2444_v2.patch">patch for Samba 3.0.24</a></td>
1259         <td>Local SID/Name translation bug can result in user privilege elevation (Updated May 25 to fix regression in the &quot;force group&quot; parameter).</td>
1260         <td>Samba 3.0.23d - 3.0.25pre2</td>
1261         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2444">CVE-2007-2444</a></td>
1262         <td><a href="/samba/security/CVE-2007-2444.html">Announcement</a></td>
1263     </tr>
1264
1265     <tr>
1266         <td>5 Feb 2007</td>
1267         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0452.patch">patch for Samba 3.0.23d</a></td>
1268         <td>Potential Denial of Service bug in smbd</td>
1269         <td>Samba 3.0.6 - 3.0.23d</td>
1270         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452">CVE-2007-0452</a></td>
1271         <td><a href="/samba/security/CVE-2007-0452.html">Announcement</a></td>
1272     </tr>
1273
1274     <tr>
1275         <td>5 Feb 2007</td>
1276         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0453.patch">patch for Samba 3.0.23d</a></td>
1277         <td>Buffer overrun in NSS host lookup Winbind library on Solaris</td>
1278         <td>Samba 3.0.21 - 3.0.23d</td>
1279         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0453">CVE-2007-0453</a></td>
1280         <td><a href="/samba/security/CVE-2007-0453.html">Announcement</a></td>
1281     </tr>
1282
1283     <tr>
1284         <td>5 Feb 2007</td>
1285         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0454.patch">patch for Samba 3.0.23d</a></td>
1286         <td>Format string bug in afsacl.so VFS plugin</td>
1287         <td>Samba 3.0.6 - 3.0.23d</td>
1288         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0454">CVE-2007-0454</a></td>
1289         <td><a href="/samba/security/CVE-2007-0454.html">Announcement</a></td>
1290     </tr>
1291
1292     <tr>
1293         <td>10 July 2006</td>
1294         <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2006-3403.patch">patch for Samba 3.0.1 - 3.0.22</a></td>
1295         <td>Memory exhaustion DoS against smbd</td>
1296         <td>Samba 3.0.1 - 3.0.22</td>
1297         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3403">CVE-2006-3403</a></td>
1298         <td><a href="/samba/security/CVE-2006-3403.html">Announcement</a></td>
1299     </tr>
1300
1301     <tr>
1302     <tr>
1303         <td>30 March 2006</td>
1304         <td><a href="/samba/ftp/patches/security/samba-3.0.21-CVE-2006-1059.patch">patch for Samba 3.0.21[a-c]</a></td>
1305         <td>Exposure of machine account credentials in winbind log files</td>
1306         <td>Samba 3.0.21 - 3.0.21c</td>
1307         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1059">CVE-2006-1059</a></td>
1308         <td><a href="/samba/security/CVE-2006-1059.html">Announcement</a></td>
1309     </tr>
1310
1311     <tr>
1312         <td>16 December 2004</td>
1313         <td><a href="/samba/ftp/patches/security/samba-3.0.9-CVE-2004-1154.patch">patch for Samba 3.0.9</a></td>
1314         <td>Integer Overflow in security descriptor parsing</td>
1315         <td>Samba 2.x, 3.0.x &lt;&#61; 3.0.9</td>
1316         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154">CVE-2004-1154</a></td>
1317         <td><a href="/samba/security/CVE-2004-1154.html">Announcement</a></td>
1318     </tr>    
1319
1320     <tr>
1321     <tr>
1322         <td>15 November 2004</td>
1323         <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0882.patch">patch for &lt;&#61;Samba 3.0.7</a></td>
1324         <td>Buffer Overrun in smbd</td>
1325         <td>Samba 3.0.x &lt;&#61; 3.0.7</td>
1326         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0882">CVE-2004-0882</a></td>
1327         <td><a href="/samba/security/CVE-2004-0882.html">Announcement</a></td>
1328     </tr>    
1329
1330     <tr>
1331         <td>8 November 2004</td>
1332         <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0930.patch">patch for &lt;&#61;Samba 3.0.7</a></td>
1333         <td>Remote DoS</td>
1334         <td>Samba 3.0.x &lt;&#61; 3.0.7</td>
1335         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0930">CVE-2004-0930</a></td>
1336         <td><a href="/samba/security/CVE-2004-0930.html">Announcement</a></td>
1337     </tr>    
1338
1339     <tr>
1340         <td>30 September 2004</td>
1341         <td><a href="/samba/ftp/stable/samba-2.2.12.tar.gz">Samba 2.2.12</a> and/or  <a href="/samba/ftp/patches/security/samba-3.0.2a-reduce_name.patch">patch for &lt;&#61;Samba 3.0.2a</a></td>
1342         <td>Potential arbitrary file access</td>
1343         <td>Samba 2.2.x &lt;&#61;2.2.11 and Samba 3.0.x &lt;&#61;3.0.2a</td>
1344         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0815">CVE-2004-0815</a></td>
1345         <td><a href="/samba/security/CVE-2004-0815.html">Announcement</a></td>
1346     </tr>    
1347         
1348       
1349       <tr>
1350         <td>13 Sept 2004</td>
1351         <td><a href="/samba/ftp/patches/security/samba-3.0.5-DoS.patch">3.0.5 patch</a></td>
1352         <td>Two DoS bugs; one affecting smbd, the other nmbd.</td>
1353         <td>3.0.x &lt;= 3.0.6</td>
1354         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0807">CVE-2004-0807</a>, <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0808">CVE-2004-0808</a></td>
1355         <td><a href="/samba/security/CVE-2004-0807_CVE-2004-0808.html">Announcement</a></td>
1356       </tr>
1357       
1358       <tr>
1359         <td>22 Jul 2004</td>
1360         <td><a href="/samba/ftp/stable/samba-3.0.5.tar.gz">3.0.5</a></td>
1361         <td>Two potential buffer overruns</td>
1362         <td>>=3.0.2</td>
1363         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0600">CVE-2004-0600</a>, 
1364             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1365         </td>
1366         <td><a href="/samba/security/CVE-2004-0600.html">CVE-2004-0600 Announcement</a>
1367             <a href="/samba/security/CVE-2004-0686.html">CVE-2004-0686 Announcement</a></td>
1368       </tr>
1369       
1370       <tr>
1371         <td>22 Jul 2004</td>
1372         <td><a href="/samba/ftp/stable/samba-2.2.10.tar.gz">2.2.10</a></td>
1373         <td>Buffer overrun in hash mangling method</td>
1374         <td>all 2.2 releases</td>
1375         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1376         </td>
1377         <td><a href="/samba/history/samba-2.2.10.html">release notes</a></td>
1378       </tr>
1379       
1380       <tr>
1381         <td>9 Feb 2004</td>
1382         <td><a href="/samba/ftp/old-versions/samba-3.0.2a.tar.gz">3.0.2a</a></td>
1383         <td align="left">Password initialization bug that could grant
1384         an attacker unauthorized
1385         access to a user account created by the mksmbpasswd.sh shell script.</td>
1386         <td>>=3.0.0</td>
1387         <td><a
1388         href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0082">CVE-2004-0082</a></td>
1389         <td><a href="/samba/security/CVE-2004-0082.html">Announcement</a></td>
1390       </tr>
1391       
1392       <tr>
1393         <td>7 Apr 2003</td>
1394         <td><a href="/samba/ftp/old-versions/samba-2.2.8a.tar.gz">2.2.8a</a></td>
1395         <td>Buffer overrun condition in the SMB/CIFS packet fragment
1396         re-assembly code.</td>
1397         <td>all 2.0 releases and <= 2.2.8</td>
1398         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0196">CVE-2003-0196</a>,
1399         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201">CVE-2003-0201</a></td>
1400         <td><a href="/samba/history/samba-2.2.8a.html">release notes</a></td>
1401       </tr>
1402       
1403       <tr>
1404         <td>10 Dec 2002</td>
1405         <td><a href="/samba/ftp/old-versions/samba-2.2.7a.tar.gz">2.2.7a</a></td>
1406         <td>Bug in the length checking for encrypted password change
1407         requests from clients.</td>
1408         <td>2.2.2 - 2.2.6</td>
1409         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0085">CVE-2003-0085</a></td>
1410         <td><a href="/samba/history/samba-2.2.7a.html">release notes</a></td>
1411       </tr>
1412       
1413       <tr>
1414         <td>23 Jun 2001</td>
1415         <td><a href="/samba/ftp/old-versions/samba-2.2.0a.tar.gz">2.2.0a</a></td>
1416         <td>Bug in expansion of certain smb.conf variables such as 
1417         %m that could grant an attacker the capability to overwrite arbitrary 
1418         files on the server.  Bug that causes smbd not to honor the hosts allow 
1419         and deny smb.conf directives.</td>
1420         <td>2.2.0</td>
1421         <td>&nbsp</td>
1422         <td><a href="/samba/history/samba-2.2.0a.html">release notes</a></td>
1423       </tr>
1424       
1425       <tr>
1426         <td>23 Jun 2001</td>
1427         <td><a href="/samba/ftp/old-versions/samba-2.0.10.tar.gz">2.0.10</a></td>
1428         <td>Bug in the handling of temporary files that allows local 
1429         users to destroy data on local devices.</td>
1430         <td>>= 2.0.0</td>
1431         <td>&nbsp</td>
1432         <td><a href="/samba/history/samba-2.0.10.html">release notes</a></td>
1433       </tr>
1434                 
1435     </table>
1436     
1437     <p><em>If you suspect you have discovered a serious security hole in a
1438 Samba release, please send an email to <a
1439 href="mailto:security@samba.org">security@samba.org</a>.</em></p>
1440
1441 <!--#include virtual="footer_history.html" -->