NEWS[4.14.4]: Samba 4.14.4, 4.13.8 and 4.12.15 Available for Download
[samba-web.git] / history / security.html
1 <!--#include virtual="/samba/header.html" --> 
2   <title>Samba - Security Updates and Information</title>
3 <!--#include virtual="header_history.html" -->
4
5 <h2>Samba Security Releases</h2>
6
7     <p>Security releases for Samba are listed below by their release
8 date. The previously affected versions of Samba are listed alongside
9 the appropriate security concern. For complete information, follow the
10 link to full release notes for each release.</p>
11
12    <p>Samba's <a href="https://wiki.samba.org/index.php/Samba_Security_Process">
13       coordinated security release and disclosure process</a> is followed
14       and new versions of Samba are released for
15       <a href="https://wiki.samba.org/index.php/Samba_Release_Planning">
16       supported Samba versions</a>.</p>
17
18     <table class="security_table">
19       <th colspan="6">Samba Security Releases</th>
20       <tr >
21         <td><em>Date Issued</em></td>
22         <td><em>Download</em></td>
23         <td><em>Known Issue(s)</em></td>
24         <td><em>Affected Releases</em></td>
25         <td><em>CVE ID #</em></td>
26         <td><em>Details</em></td>
27       </tr>
28
29     <tr>
30         <td>29 Apr 2021</td>
31         <td><a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
32         patch for Samba 4.14.3</a><br />
33         <a href="/samba/ftp/patches/security/samba-4.13.7-security-2021-04-29.patch">
34         patch for Samba 4.13.7</a><br />
35         <a href="/samba/ftp/patches/security/samba-4.12.14-security-2021-04-29.patch">
36         patch for Samba 4.12.14</a><br />
37         </td>
38         <td>Negative idmap cache entries can cause incorrect group entries in
39             the Samba file server process token.
40         </td>
41         <td>All versions since 3.6.0.</td>
42         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20254">CVE-2021-20254</a>
43         </td>
44         <td><a href="/samba/security/CVE-2021-20254.html">Announcement</a>
45         </td>
46     </tr>
47
48     <tr>
49         <td>24 Mar 2021</td>
50         <td><a href="/samba/ftp/patches/security/samba-4.14.0-security-2021-03-24.patch">
51         patch for Samba 4.14.0</a><br />
52         <a href="/samba/ftp/patches/security/samba-4.13.5-security-2021-03-24.patch">
53         patch for Samba 4.13.5</a><br />
54         <a href="/samba/ftp/patches/security/samba-4.12.12-security-2021-03-24.patch">
55         patch for Samba 4.12.12</a><br />
56         </td>
57         <td>CVE-2020-27840 and CVE-2021-20277. Please see announcements for details.
58         </td>
59         <td>Please refer to the advisories.</td>
60         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27840">CVE-2020-27840</a>,
61         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20277">CVE-2021-20277</a>.
62         </td>
63         <td><a href="/samba/security/CVE-2020-27840.html">Announcement</a>,
64         <a href="/samba/security/CVE-2021-20277.html">Announcement</a>.
65         </td>
66     </tr>
67
68     <tr>
69         <td>29 Oct 2020</td>
70         <td><a href="/samba/ftp/patches/security/samba-4.13.0-security-2020-10-29.patch">
71         patch for Samba 4.13.0</a><br />
72         <a href="/samba/ftp/patches/security/samba-4.12.8-security-2020-10-29.patch">
73         patch for Samba 4.12.8</a><br />
74         <a href="/samba/ftp/patches/security/samba-4.11.14-security-2020-10-29.patch">
75         patch for Samba 4.11.14</a><br />
76         </td>
77         <td>CVE-2020-14318, CVE-2020-14323 and CVE-2020-14383. Please see announcements for details.
78         </td>
79         <td>Please refer to the advisories.</td>
80         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14318">CVE-2020-14318</a>,
81         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14323">CVE-2020-14323</a>
82         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14383">CVE-2020-14383</a>.
83         </td>
84         <td><a href="/samba/security/CVE-2020-14318.html">Announcement</a>,
85         <a href="/samba/security/CVE-2020-14323.html">Announcement</a>,
86         <a href="/samba/security/CVE-2020-14383.html">Announcement</a>.
87         </td>
88     </tr>
89
90     <tr>
91         <td>18 Sep 2020</td>
92         <td><a href="/samba/ftp/patches/security/samba-4.12.6-security-2020-09-18.patch">
93         patch for Samba 4.12.6</a><br />
94         <a href="/samba/ftp/patches/security/samba-4.11.12-security-2020-09-18.patch">
95         patch for Samba 4.11.12</a><br />
96         <a href="/samba/ftp/patches/security/samba-4.10.17-security-2020-09-18.patch">
97         patch for Samba 4.10.17</a><br />
98         </td>
99         <td>CVE-2020-1472.
100             Please see announcements for details.
101         </td>
102         <td>Please refer to the advisory.</td>
103         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1472">CVE-2020-1472</a>.
104         </td>
105         <td><a href="/samba/security/CVE-2020-1472.html">Announcement</a>,
106         </td>
107     </tr>
108
109     <tr>
110         <td>02 Jul 2020</td>
111         <td><a href="/samba/ftp/patches/security/samba-4.12.3-security-2020-07-02.patch">
112         patch for Samba 4.12.3</a><br />
113         <a href="/samba/ftp/patches/security/samba-4.11.10-security-2020-07-02.patch">
114         patch for Samba 4.11.10</a><br />
115         <a href="/samba/ftp/patches/security/samba-4.10.16-security-2020-07-02.patch">
116         patch for Samba 4.10.16</a><br />
117         </td>
118         <td>CVE-2020-10730, CVE-2020-10745, CVE-2020-10760 and CVE-2020-14303.
119             Please see announcements for details.
120         </td>
121         <td>Please refer to the advisories.</td>
122         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10730">CVE-2020-10730</a>,
123         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10745">CVE-2020-10745</a>,
124         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10760">CVE-2020-10760</a>,
125         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14303">CVE-2020-14303</a>.
126         </td>
127         <td><a href="/samba/security/CVE-2020-10730.html">Announcement</a>,
128         <a href="/samba/security/CVE-2020-10745.html">Announcement</a>,
129         <a href="/samba/security/CVE-2020-10760.html">Announcement</a>,
130         <a href="/samba/security/CVE-2020-14303.html">Announcement</a>
131         </td>
132     </tr>
133
134     <tr>
135         <td>28 Apr 2020</td>
136         <td><a href="/samba/ftp/patches/security/samba-4.12.1-security-2020-04-28.patch">
137         patch for Samba 4.12.1</a><br />
138         <a href="/samba/ftp/patches/security/samba-4.11.7-security-2020-04-28.patch">
139         patch for Samba 4.11.7</a><br />
140         <a href="/samba/ftp/patches/security/samba-4.10.14-security-2020-04-28.patch">
141         patch for Samba 4.10.14</a><br />
142         </td>
143         <td>CVE-2020-10700 and CVE-2020-10704. Please see announcements for
144         details.
145         </td>
146         <td>Please refer to the advisories.</td>
147         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10700">CVE-2020-10700</a>,
148         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10704">CVE-2020-10704</a>.
149         </td>
150         <td><a href="/samba/security/CVE-2020-10700.html">Announcement</a>,
151         <a href="/samba/security/CVE-2020-10704.html">Announcement</a>
152         </td>
153     </tr>
154
155     <tr>
156         <td>21 Jan 2020</td>
157         <td><a href="/samba/ftp/patches/security/samba-4.11.4-security-2020-01-21.patch">
158         patch for Samba 4.11.4</a><br />
159         <a href="/samba/ftp/patches/security/samba-4.10.11-security-2020-01-21.patch">
160         patch for Samba 4.10.11</a><br />
161         <a href="/samba/ftp/patches/security/samba-4.9.17-security-2020-01-21.patch">
162         patch for Samba 4.9.17</a><br />
163         </td>
164         <td>CVE-2019-14902, CVE-2019-14907 and CVE-2019-19344. Please see announcements for
165         details.
166         </td>
167         <td>Please refer to the advisories.</td>
168         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14902">CVE-2019-14902</a>,
169         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14907">CVE-2019-14907</a>,
170         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19344">CVE-2019-19344.</a>.
171         </td>
172         <td><a href="/samba/security/CVE-2019-14902.html">Announcement</a>,
173         <a href="/samba/security/CVE-2019-14907.html">Announcement</a>,
174         <a href="/samba/security/CVE-2019-19344.html">Announcement</a>
175         </td>
176     </tr>
177
178     <tr>
179         <td>10 Dec 2019</td>
180         <td><a
181 href="/samba/ftp/patches/security/samba-4.11.2-security-2019-12-10.patch">
182         patch for Samba 4.11.2</a><br />
183         <a href="/samba/ftp/patches/security/samba-4.10.10-security-2019-12-10.patch">
184         patch for Samba 4.10.10</a><br />
185         <a href="/samba/ftp/patches/security/samba-4.9.16-security-2019-12-10.patch">
186         patch for Samba 4.9.16</a><br />
187         </td>
188         <td>CVE-2019-14861 and CVE-2019-14870. Please see announcements for
189         details.
190         </td>
191         <td>All versions since Samba 4.0</td>
192         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14861">CVE-2019-14861</a>,
193         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14870">CVE-2019-14870</a>.
194         </td>
195         <td><a href="/samba/security/CVE-2019-14861.html">Announcement</a>,
196         <a href="/samba/security/CVE-2019-14870.html">Announcement</a>
197         </td>
198     </tr>
199
200     <tr>
201         <td>29 Oct 2019</td>
202         <td><a href="/samba/ftp/patches/security/samba-4.11.1-security-2019-10-29.patch">
203         patch for Samba 4.11.1</a><br />
204         <a href="/samba/ftp/patches/security/samba-4.10.9-security-2019-10-29.patch">
205         patch for Samba 4.10.9</a><br />
206         <a href="/samba/ftp/patches/security/samba-4.9.14-security-2019-10-29.patch">
207         patch for Samba 4.9.14</a><br />
208         </td>
209         <td>CVE-2019-10218, CVE-2019-14833 and CVE-2019-14847. Please see
210         announcements for details.
211         </td>
212         <td>please refer to the advisories</td>
213         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10218">CVE-2019-10218</a>,
214         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14833">CVE-2019-14833</a>,
215         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14847">CVE-2019-14847</a>
216         </td>
217         <td><a href="/samba/security/CVE-2019-10218.html">Announcement</a>,
218         <a href="/samba/security/CVE-2019-14833.html">Announcement</a>,
219         <a href="/samba/security/CVE-2019-14847.html">Announcement</a>
220         </td>
221     </tr>
222
223     <tr>
224         <td>03 Sep 2019</td>
225         <td><a href="/samba/ftp/patches/security/samba-4.10.7-CVE-2019-10197.patch">
226         patch for Samba 4.10.7</a><br />
227         <a href="/samba/ftp/patches/security/samba-4.9.12-CVE-2019-10197.patch">
228         patch for Samba 4.9.12</a><br />
229         </td>
230         <td>Combination of parameters and permissions can allow user to escape
231             from the share path definition.
232         </td>
233         <td>All versions between Samba 4.9.0 and 4.9.12/4.10.7 (incl.).</td>
234         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10197">CVE-2019-10197</a>
235         </td>
236         <td><a href="/samba/security/CVE-2019-10197.html">Announcement</a>
237         </td>
238     </tr>
239
240     <tr>
241         <td>19 Jun 2019</td>
242         <td><a href="/samba/ftp/patches/security/samba-4.10.4-security-2019-06-19.patch">
243         patch for Samba 4.10.4 (both CVEs)</a><br />
244         <a href="/samba/ftp/patches/security/samba-4.9.8-security-2019-06-19.patch">
245         patch for Samba 4.9.8 (CVE-2019-12435 only)</a><br />
246         </td>
247         <td>CVE-2019-12435 and CVE-2019-12436. Please see the announcements for details.
248         </td>
249         <td>please refer to the advisories</td>
250         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12435">CVE-2019-12435</a>,
251         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12436">CVE-2019-12436</a>
252         </td>
253         <td><a href="/samba/security/CVE-2019-12435.html">Announcement</a>,
254         <a href="/samba/security/CVE-2019-12436.html">Announcement</a>
255         </td>
256     </tr>
257
258     <tr>
259         <td>14 May 2019</td>
260         <td><a href="/samba/ftp/patches/security/samba-4.10.2-security-2019-05-14.patch">
261         patch for Samba 4.10.2</a><br />
262         <a href="/samba/ftp/patches/security/samba-4.9.7-security-2019-05-14.patch">
263         patch for Samba 4.9.7</a><br />
264         <a href="/samba/ftp/patches/security/samba-4.8.11-security-2019-05-14.patch">
265         patch for Samba 4.8.11</a><br />
266         </td>
267         <td>CVE-2018-16860. Please see the announcements for details.
268         </td>
269         <td>All versions of Samba prior to 4.10.3, 4.9.8, 4.8.12.</td>
270         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16860">CVE-2018-16860</a>
271         </td>
272         <td><a href="/samba/security/CVE-2018-16860.html">Announcement</a>
273         </td>
274     </tr>
275
276     <tr>
277         <td>08 Apr 2019</td>
278         <td><a href="/samba/ftp/patches/security/samba-4.10.1-security-2019-04-08.patch">
279         patch for Samba 4.10.1 (both CVEs)</a><br />
280         <a href="/samba/ftp/patches/security/samba-4.9.5-security-2019-04-08.patch">
281         patch for Samba 4.9.5 (both CVEs)</a><br />
282         <a href="/samba/ftp/patches/security/samba-4.8.10-security-2019-04-08.patch">
283         patch for Samba 4.8.10 (CVE-2019-3880 only)</a><br />
284         </td>
285         <td>CVE-2019-3870 and CVE-2019-3880. Please see the announcements for details.
286         </td>
287         <td>please refer to the advisories</td>
288         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3870">CVE-2019-3870</a>,
289             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3880">CVE-2019-3880</a>
290         </td>
291         <td><a href="/samba/security/CVE-2019-3870.html">Announcement</a>,
292             <a href="/samba/security/CVE-2019-3880.html">Announcement</a>
293         </td>
294     </tr>
295
296     <tr>
297         <td>27 Nov 2018</td>
298         <td><a href="/samba/ftp/patches/security/samba-4.9.2-security-2018-11-27.patch">
299         patch for Samba 4.9.2 (all CVEs)</a><br />
300         <a href="/samba/ftp/patches/security/samba-4.8.6-security-2018-11-27.patch">
301         patch for Samba 4.8.6 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
302         <a href="/samba/ftp/patches/security/samba-4.7.11-security-2018-11-27.patch">
303         patch for Samba 4.7.11 (all CVEs except CVE-2018-16852 and CVE-2018-16857)</a><br />
304         <td>Numerous CVEs. Please see the announcements for details.
305         </td>
306         <td>please refer to the advisories</td>
307         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14629">CVE-2018-14629</a>,
308             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16841">CVE-2018-16841</a>,
309             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16851">CVE-2018-16851</a>,
310             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16852">CVE-2018-16852</a>,
311             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16853">CVE-2018-16853</a>,
312             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16857">CVE-2018-16857</a>
313         </td>
314         <td><a href="/samba/security/CVE-2018-14629.html">Announcement</a>,
315             <a href="/samba/security/CVE-2018-16841.html">Announcement</a>,
316             <a href="/samba/security/CVE-2018-16851.html">Announcement</a>,
317             <a href="/samba/security/CVE-2018-16852.html">Announcement</a>,
318             <a href="/samba/security/CVE-2018-16853.html">Announcement</a>,
319             <a href="/samba/security/CVE-2018-16857.html">Announcement</a>
320         </td>
321     </tr>
322
323     <tr>
324         <td>14 Aug 2018</td>
325         <td><a href="/samba/ftp/patches/security/samba-4.8.3-security-2018-08-14.patch">
326         patch for Samba 4.8.3 (all CVEs)</a><br />
327         <a href="/samba/ftp/patches/security/samba-4.7.8-security-2018-08-14.patch">
328         patch for Samba 4.7.8 (all CVEs except CVE-2018-1140)</a><br />
329         <a href="/samba/ftp/patches/security/samba-4.6.15-security-2018-08-14.patch">
330         patch for Samba 4.6.15 (CVE-2018-10858 and CVE-2018-10919)</a><br />
331         <td>Numerous CVEs. Please see the announcements for details.
332         </td>
333         <td>please refer to the advisories</td>
334         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10858">CVE-2018-10858</a>,
335             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10918">CVE-2018-10918</a>,
336             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10919">CVE-2018-10919</a>,
337             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1139">CVE-2018-1139</a>,
338             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1140">CVE-2018-1140</a>
339         </td>
340         <td><a href="/samba/security/CVE-2018-10858.html">Announcement</a>,
341             <a href="/samba/security/CVE-2018-10918.html">Announcement</a>,
342             <a href="/samba/security/CVE-2018-10919.html">Announcement</a>,
343             <a href="/samba/security/CVE-2018-1139.html">Announcement</a>,
344             <a href="/samba/security/CVE-2018-1140.html">Announcement</a>
345         </td>
346     </tr>
347
348     <tr>
349         <td>13 Mar 2018</td>
350         <td><a href="/samba/ftp/patches/security/samba-4.7.5-security-2018-03-13.patch">
351         patch for Samba 4.7.5</a><br />
352         <a href="/samba/ftp/patches/security/samba-4.6.13-security-2018-03-13.patch">
353         patch for Samba 4.6.13</a><br />
354         <a href="/samba/ftp/patches/security/samba-4.5.15-security-2018-03-13.patch">
355         patch for Samba 4.5.15</a><br />
356         <a href="/samba/ftp/patches/security/samba-4.4.16-CVE-2018-1057.patch">
357         patch for Samba 4.4.16 (only CVE-2018-1057)</a><br />
358         <a href="/samba/ftp/patches/security/samba-4.3.13-CVE-2018-1057.patch">
359         patch for Samba 4.3.13 (only CVE-2018-1057)</a><br />
360         <td>Numerous CVEs. Please see the announcements for details.
361         </td>
362         <td>please refer to the advisories</td>
363         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1050">CVE-2018-1050</a>,
364             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1057">CVE-2018-1057</a>
365         </td>
366         <td><a href="/samba/security/CVE-2018-1050.html">Announcement</a>, 
367             <a href="/samba/security/CVE-2018-1057.html">Announcement</a>
368         </td>
369     </tr>
370
371     <tr>
372         <td>21 Nov 2017</td>
373         <td><a href="/samba/ftp/patches/security/samba-4.7.2-security-2017-11-21.patch">
374         patch for Samba 4.7.2</a><br />
375         <a href="/samba/ftp/patches/security/samba-4.6.10-security-2017-11-21.patch">
376         patch for Samba 4.6.10</a><br />
377         <a href="/samba/ftp/patches/security/samba-4.5.14-security-2017-11-21.patch">
378         patch for Samba 4.5.14</a><br />
379         <td>Numerous CVEs. Please see the announcements for details.
380         </td>
381         <td>please refer to the advisories</td>
382         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14746">CVE-2017-14746</a>, 
383             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15275">CVE-2017-15275</a>
384         </td>
385         <td><a href="/samba/security/CVE-2017-14746.html">Announcement</a>, 
386             <a href="/samba/security/CVE-2017-15275.html">Announcement</a>
387         </td>
388     </tr>
389
390     <tr>
391         <td>20 Sep 2017</td>
392         <td><a href="/samba/ftp/patches/security/samba-4.6.7-security-2017-09-20.patch">
393         patch for Samba 4.6.7</a><br />
394         <a href="/samba/ftp/patches/security/samba-4.5.13-security-2017-09-20.patch">
395         patch for Samba 4.5.13</a><br />
396         <a href="/samba/ftp/patches/security/samba-4.4.15-security-2017-09-20.patch">
397         patch for Samba 4.4.15</a><br />
398         <td>Numerous CVEs. Please see the announcements for details.
399         </td>
400         <td>please refer to the advisories</td>
401         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12150">CVE-2017-12150</a>, 
402             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12151">CVE-2017-12151</a>, 
403             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12163">CVE-2017-12163</a>
404         </td>
405         <td><a href="/samba/security/CVE-2017-12150.html">Announcement</a>, 
406             <a href="/samba/security/CVE-2017-12151.html">Announcement</a>, 
407             <a href="/samba/security/CVE-2017-12163.html">Announcement</a>
408         </td>
409     </tr>
410
411     <tr>
412         <td>12 July 2017</td>
413         <td><a href="/samba/ftp/patches/security/samba-4.x.y-CVE-2017-11103.patch">
414         patch for Samba 4.x.y</a><br />
415         <td>Orpheus&apos; Lyre mutual authentication validation bypass.
416         </td>
417         <td>All versions between Samba 4.0.0 and 4.6.6/4.5.12/4.4.15</td>
418         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11103">CVE-2017-11103</a>
419         </td>
420         <td><a href="/samba/security/CVE-2017-11103.html">Announcement</a>
421         </td>
422     </tr>
423
424     <tr>
425         <td>24 May 2017</td>
426         <td><a href="/samba/ftp/patches/security/samba-4.6.3-4.5.9-4.4.13-CVE-2017-7494.patch">
427         patch for Samba 4.6.3, 4.5.9, 4.4.13</a><br />
428         <td>Remote code execution from a writable share.
429         </td>
430         <td>All versions between Samba 3.5.0 and 4.6.4/4.5.10/4.4.14</td>
431         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7494">CVE-2017-7494</a>
432         </td>
433         <td><a href="/samba/security/CVE-2017-7494.html">Announcement</a>
434         </td>
435     </tr>
436
437     <tr>
438         <td>23 Mar 2017</td>
439         <td><a href="/samba/ftp/patches/security/samba-4.6.0-CVE-2017-2619.patch">
440         patch for Samba 4.6.0</a><br />
441         <a href="/samba/ftp/patches/security/samba-4.5.6-CVE-2017-2619.patch">
442         patch for Samba 4.5.6</a><br />
443         <a href="/samba/ftp/patches/security/samba-4.4.11-CVE-2017-2619.patch">
444         patch for Samba 4.4.11</a><br />
445         <td>Symlink race allows access outside share definition.
446         </td>
447         <td>All versions of Samba prior to 4.6.1, 4.5.7, 4.4.12</td>
448         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2619">CVE-2017-2619</a>
449         </td>
450         <td><a href="/samba/security/CVE-2017-2619.html">Announcement</a>
451         </td>
452     </tr>
453
454     <tr>
455         <td>19 Dec 2016</td>
456         <td><a href="/samba/ftp/patches/security/samba-4.5.2-security-20016-12-19.patch">
457         patch for Samba 4.5.2</a><br />
458         <a href="/samba/ftp/patches/security/samba-4.4.7-security-20016-12-19.patch">
459         patch for Samba 4.4.7</a><br />
460         <a href="/samba/ftp/patches/security/samba-4.3.12-security-20016-12-19.patch">
461         patch for Samba 4.3.12</a><br />
462         <td>Numerous CVEs. Please see the announcements for details.
463         </td>
464         <td>please refer to the advisories</td>
465         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2123">CVE-2016-2123</a>, 
466             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2125">CVE-2016-2125</a>, 
467             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2126">CVE-2016-2126</a>
468         </td>
469         <td><a href="/samba/security/CVE-2016-2123.html">Announcement</a>, 
470             <a href="/samba/security/CVE-2016-2125.html">Announcement</a>, 
471             <a href="/samba/security/CVE-2016-2126.html">Announcement</a>
472         </td>
473     </tr>
474
475     <tr>
476         <td>07 Jul 2016</td>
477         <td><a href="/samba/ftp/patches/security/samba-4.4.4-CVE-2016-2119.patch">
478         patch for Samba 4.4.4</a><br />
479         <a href="/samba/ftp/patches/security/samba-4.3.10-CVE-2016-2119.patch">
480         patch for Samba 4.3.10</a><br />
481         <a href="/samba/ftp/patches/security/samba-4.2.13-CVE-2016-2119.patch">
482         patch for Samba 4.2.13</a><br />
483         <td>Client side SMB2/3 required signing can be downgraded.
484         </td>
485         <td>4.0.0 - 4.4.4</td>
486         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2119">CVE-2016-2119</a>
487         </td>
488         <td><a href="/samba/security/CVE-2016-2119.html">Announcement</a>
489         </td>
490     </tr>
491
492     <tr>
493         <td>12 Apr 2016</td>
494         <td><a href="/samba/ftp/patches/security/samba-4.4.0-security-2016-04-12-final.patch">
495         patch for Samba 4.4.0</a><br />
496         <a href="/samba/ftp/patches/security/samba-4.3.6-security-2016-04-12-final.patch">
497         patch for Samba 4.3.6</a><br />
498         <a href="/samba/ftp/patches/security/samba-4.2.9-security-2016-04-12-final.patch">
499         patch for Samba 4.2.9</a><br />
500         <a href="/samba/ftp/patches/security/samba-v4-0-security-2016-04-12-fileserver-only.patch.xz">
501         patch for Samba 4.0.26 (fileserver only! no client! no domain controller!)</a><br />
502         <a href="/samba/ftp/patches/security/samba-v3-6-security-2016-04-12.tar.xz">
503         patch for Samba 3.6.25 (only related CVEs)</a><br />
504         <td>Numerous CVEs. Please see the announcements for details.
505         </td>
506         <td>please refer to the advisories</td>
507         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5370">CVE-2015-5370</a>, 
508             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2110">CVE-2016-2110</a>, 
509             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2111">CVE-2016-2111</a>, 
510             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2112">CVE-2016-2112</a>, 
511             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2113">CVE-2016-2113</a>, 
512             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2114">CVE-2016-2114</a>, 
513             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2115">CVE-2016-2115</a>, 
514             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2118">CVE-2016-2118</a>
515         </td>
516         <td><a href="/samba/security/CVE-2015-5370.html">Announcement</a>
517             <a href="/samba/security/CVE-2016-2110.html">Announcement</a>
518             <a href="/samba/security/CVE-2016-2111.html">Announcement</a>
519             <a href="/samba/security/CVE-2016-2112.html">Announcement</a>
520             <a href="/samba/security/CVE-2016-2113.html">Announcement</a>
521             <a href="/samba/security/CVE-2016-2114.html">Announcement</a>
522             <a href="/samba/security/CVE-2016-2115.html">Announcement</a>
523             <a href="/samba/security/CVE-2016-2118.html">Announcement</a>
524         </td>
525     </tr>
526
527     <tr>
528         <td>08 Mar 2016</td>
529         <td><a href="/samba/ftp/patches/security/samba-4.3.5-security-2016-03-08.patch">
530         patch for Samba 4.3.5</a><br />
531         <a href="/samba/ftp/patches/security/samba-4.2.8-security-2016-03-08.patch">
532         patch for Samba 4.2.8</a><br />
533         <a href="/samba/ftp/patches/security/samba-4.1.22-security-2016-03-08.patch">
534         patch for Samba 4.1.22</a><br />
535         <td>Incorrect ACL get/set allowed on symlink path, Out-of-bounds read in internal DNS server.
536         </td>
537         <td>please refer to the advisories</td>
538         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7560">CVE-2015-7560</a>, 
539             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0771">CVE-2016-0771</a>, 
540         </td>
541         <td><a href="/samba/security/CVE-2015-7560.html">Announcement</a>
542             <a href="/samba/security/CVE-2016-0771.html">Announcement</a>
543         </td>
544     </tr>
545
546     <tr>
547         <td>16 Dec 2015</td>
548         <td><a href="/samba/ftp/patches/security/samba-4.3.2-security-2015-12-16.patch">
549         patch for Samba 4.3.2</a><br />
550         <a href="/samba/ftp/patches/security/samba-4.2.6-security-2015-12-16.patch">
551         patch for Samba 4.2.6</a><br />
552         <a href="/samba/ftp/patches/security/samba-4.1.21-security-2015-12-16.patch">
553         patch for Samba 4.1.21</a><br />
554         <a href="/samba/ftp/patches/security/samba-3.6.25-security-2015-12-16.patch">
555         patch for Samba 3.6.25</a><br />
556         <td>Numerous CVEs. Please see the announcements for details.
557         </td>
558         <td>3.0.0 to 4.3.2</td>
559         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3223">CVE-2015-3223</a>, 
560             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5252">CVE-2015-5252</a>, 
561             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5296">CVE-2015-5296</a>, 
562             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5299">CVE-2015-5299</a>, 
563             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5330">CVE-2015-5330</a>, 
564             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7540">CVE-2015-7540</a>, 
565             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8467">CVE-2015-8467</a>
566         </td>
567         <td><a href="/samba/security/CVE-2015-3223.html">Announcement</a>
568             <a href="/samba/security/CVE-2015-5252.html">Announcement</a>
569             <a href="/samba/security/CVE-2015-5296.html">Announcement</a>
570             <a href="/samba/security/CVE-2015-5299.html">Announcement</a>
571             <a href="/samba/security/CVE-2015-5330.html">Announcement</a>
572             <a href="/samba/security/CVE-2015-7540.html">Announcement</a>
573             <a href="/samba/security/CVE-2015-8467.html">Announcement</a>
574         </td>
575     </tr>
576
577     <tr>
578         <td>23 Feb 2015</td>
579         <td><a href="/samba/ftp/patches/security/samba-4.1.16-CVE-2015-0240.patch">
580         patch for Samba 4.1.16</a><br />
581         <a href="/samba/ftp/patches/security/samba-4.0.24-CVE-2015-0240.patch">
582         patch for Samba 4.0.24</a><br />
583         <a href="/samba/ftp/patches/security/samba-3.6.24-CVE-2015-0240.patch">
584         patch for Samba 3.6.24</a><br />
585         <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2015-0240.patch">
586         patch for Samba 3.5.22</a><br />
587         <td>Unexpected code execution in smbd.
588         </td>
589         <td>3.5.0 - 4.2.0rc4</td>
590         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0240">CVE-2015-0240</a>
591         </td>
592         <td><a href="/samba/security/CVE-2015-0240.html">Announcement</a>
593         </td>
594     </tr>
595
596     <tr>
597         <td>15 Jan 2015</td>
598         <td><a href="/samba/ftp/patches/security/samba-4.1.15-CVE-2014-8143.patch">
599         patch for Samba 4.1.15</a><br />
600         <a href="/samba/ftp/patches/security/samba-4.0.23-CVE-2014-8143.patch">
601         patch for Samba 4.0.23</a><br />
602         <td>Elevation of privilege to Active Directory Domain Controller.
603         </td>
604         <td>4.0.0 - 4.1.15</td>
605         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8143">CVE-2014-8143</a>
606         </td>
607         <td><a href="/samba/security/CVE-2014-8143.html">Announcement</a>
608         </td>
609     </tr>
610
611     <tr>
612         <td>01 Aug 2014</td>
613         <td><a href="/samba/ftp/patches/security/samba-4.1.10-CVE-2014-3560.patch">
614         patch for Samba 4.1.10</a><br />
615         <a href="/samba/ftp/patches/security/samba-4.0.20-CVE-2014-3560.patch">
616         patch for Samba 4.0.20</a><br />
617         <td>Remote code execution in nmbd.
618         </td>
619         <td>4.0.0 - 4.1.10</td>
620         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3560">CVE-2014-3560</a>
621         </td>
622         <td><a href="/samba/security/CVE-2014-3560.html">Announcement</a>
623         </td>
624     </tr>
625
626     <tr>
627         <td>23 Jun 2014</td>
628         <td><a href="/samba/ftp/patches/security/samba-4.1.8-CVE-2014-0244-CVE-2014-3493.patch">
629         patch for Samba 4.1.8</a><br />
630         <a href="/samba/ftp/patches/security/samba-4.0.18-CVE-2014-0244-CVE-2014-3493.patch">
631         patch for Samba 4.0.18</a><br />
632         <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0244-CVE-2014-3493.patch">
633         patch for Samba 3.6.23</a><br />
634         <td>Denial of service - CPU loop, Denial of service - Server crash/memory corruption.
635         </td>
636         <td>please refer to the advisories</td>
637         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0244">CVE-2014-0244</a>, 
638             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3493">CVE-2014-3493</a>
639         </td>
640         <td><a href="/samba/security/CVE-2014-0244.html">Announcement</a>
641             <a href="/samba/security/CVE-2014-3493.html">Announcement</a>
642         </td>
643     </tr>
644
645     <tr>
646         <td>03 June 2014</td>
647         <td><a href="/samba/ftp/patches/security/samba-4.0.17-CVE-2014-0178-CVE-2014-0239.patch">
648         patch for Samba 4.0.17</a><br />
649         <a href="/samba/ftp/patches/security/samba-4.1.7-CVE-2014-0178-CVE-2014-0239.patch">
650         patch for Samba 4.1.7</a><br />
651         <a href="/samba/ftp/patches/security/samba-3.6.23-CVE-2014-0178.patch">
652         patch for Samba 3.6.23 (CVE-2014-0178 only)</a><br />
653         <td>Uninitialized memory exposure, Potential DOS in Samba internal DNS server.
654         </td>
655         <td>please refer to the advisories</td>
656         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0178">CVE-2014-0178</a>, 
657             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0239">CVE-2014-0239</a>
658         </td>
659         <td><a href="/samba/security/CVE-2014-0178.html">Announcement</a>
660             <a href="/samba/security/CVE-2014-0239.html">Announcement</a>
661         </td>
662     </tr>
663
664     <tr>
665         <td>11 Mar 2014</td>
666         <td><a href="/samba/ftp/patches/security/samba-4.1.5-CVE-2013-4496-CVE-2013-6442.patch">
667         patch for Samba 4.1.5</a><br />
668         <a href="/samba/ftp/patches/security/samba-4.0.15-CVE-2013-4496-CVE-2013-6442.patch">
669         patch for Samba 4.0.15</a><br />
670         <a href="/samba/ftp/patches/security/samba-3.6.22-CVE-2013-4496.patch">
671         patch for Samba 3.6.22</a><br />
672         <td>Password lockout not enforced for SAMR password changes, smbcacls can remove a file
673         or directory ACL by mistake.
674         </td>
675         <td>please refer to the advisories</td>
676         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496">CVE-2013-4496</a>, 
677             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6442">CVE-2013-6442</a>
678         </td>
679         <td><a href="/samba/security/CVE-2013-4496.html">Announcement</a>
680             <a href="/samba/security/CVE-2013-6442.html">Announcement</a>
681         </td>
682     </tr>
683
684     <tr>
685         <td>09 Dec 2013</td>
686         <td><a href="/samba/ftp/patches/security/samba-4.1.2-CVE-2013-4408-CVE-2012-6150.patch">
687         patch for Samba 4.1.2</a><br />
688         <a href="/samba/ftp/patches/security/samba-4.0.12-CVE-2013-4408-CVE-2012-6150.patch">
689         patch for Samba 4.0.12</a><br />
690         <a href="/samba/ftp/patches/security/samba-3.6.21-CVE-2013-4408-CVE-2012-6150.patch">
691         patch for Samba 3.6.21</a><br />
692         <a href="/samba/ftp/patches/security/samba-3.5.22-CVE-2013-4408.patch">
693         patch for Samba 3.5.22</a><br />
694         <a href="/samba/ftp/patches/security/samba-3.4.17-CVE-2013-4408.patch">
695         patch for Samba 3.4.17</a>
696         <td>DCE-RPC fragment length field is incorrectly checked, pam_winbind
697         login without require_membership_of restrictions.</td>
698         <td>please refer to the advisories</td>
699         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408">CVE-2013-4408</a>, 
700             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150">CVE-2012-6150</a>
701         </td>
702         <td><a href="/samba/security/CVE-2013-4408.html">Announcement</a>
703             <a href="/samba/security/CVE-2012-6150.html">Announcement</a>
704         </td>
705     </tr>
706
707     <tr>
708         <td>11 Nov 2013</td>
709         <td><a href="/samba/ftp/patches/security/samba-4.1.0-CVE-2013-4475-CVE-2013-4476.patch">
710         patch for Samba 4.1.0</a><br />
711         <a href="/samba/ftp/patches/security/samba-4.0.10-CVE-2013-4475-CVE-2013-4476.patch">
712         patch for Samba 4.0.10</a><br />
713         <a href="/samba/ftp/patches/security/samba-3.6.19-CVE-2013-4475.patch">
714         patch for Samba 3.6.19</a><br />
715         <td>ACLs are not checked on opening an alternate data stream on a file
716             or directory, Private key in key.pem world readable.</td>
717         <td>3.2.0 - 4.1.0, 4.0.0 - 4.0.10, 4.1.0</td>
718         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4475">CVE-2013-4475</a>, 
719             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4476">CVE-2013-4476</a>
720         </td>
721         <td><a href="/samba/security/CVE-2013-4475.html">Announcement</a>
722             <a href="/samba/security/CVE-2013-4476.html">Announcement</a>
723         </td>
724     </tr>
725
726     <tr>
727         <td>05 Aug 2013</td>
728         <td><a href="/samba/ftp/patches/security/samba-4.0.7-CVE-2013-4124.patch">
729         patch for Samba 4.0.7</a><br />
730         <a href="/samba/ftp/patches/security/samba-3.6.16-CVE-2013-4124.patch">
731         patch for Samba 3.6.16</a><br />
732         <a href="/samba/ftp/patches/security/samba-3.5.21-CVE-2013-4124.patch">
733         patch for Samba 3.5.21</a><br />
734         <td>Denial of service - CPU loop and memory allocation.</td>
735         <td>3.0.x-4.0.7</td>
736         <td><a
737         href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124">CVE-2013-4124</a>
738         </td>
739         <td><a href="/samba/security/CVE-2013-4124.html">Announcement</a>
740         </td>
741     </tr>
742
743     <tr>
744         <td>02 Apr 2013</td>
745         <td><a href="/samba/ftp/patches/security/samba-3.6-CVE-2013-0454.patch">
746         patch for Samba 3.6.5</a>
747         <td>A writable configured share might get read only</td>
748         <td>3.6.0 - 3.6.5 (inclusive)</td>
749         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0454">CVE-2013-0454</a>
750         </td>
751         <td><a href="/samba/security/CVE-2013-0454.html">Announcement</a>
752         </td>
753     </tr>
754
755     <tr>
756         <td>19 Mar 2013</td>
757         <td><a href="/samba/ftp/patches/security/samba-4.0.3-CVE-2013-1863.patch">
758         patch for Samba 4.0.3</a>
759         <td>World-writeable files may be created in additional shares on a Samba
760         4.0 AD DC.</td>
761         <td>4.0.0rc6-4.0.3</td>
762         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1863">CVE-2013-1863</a>
763         </td>
764         <td><a href="/samba/security/CVE-2013-1863.html">Announcement</a>
765         </td>
766     </tr>
767
768     <tr>
769         <td>30 Jan 2013</td>
770         <td><a href="/samba/ftp/patches/security/samba-4.0.1-CVE-2013-0213-CVE-2013-0214.patch">
771         patch for Samba 4.0.1</a><br />
772         <a href="/samba/ftp/patches/security/samba-3.6.11-CVE-2013-0213-CVE-2013-0214.patch">
773         patch for Samba 3.6.11</a><br />
774         <a href="/samba/ftp/patches/security/samba-3.5.20-CVE-2013-0213-CVE-2013-0214.patch">
775         patch for Samba 3.5.20</a><br />
776         <td>Clickjacking issue and potential XSRF in SWAT.</td>
777         <td>3.0.x-4.0.1</td>
778         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0213">CVE-2013-0213</a>, 
779             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0214">CVE-2013-0214</a>
780         </td>
781         <td><a href="/samba/security/CVE-2013-0213.html">Announcement</a>
782             <a href="/samba/security/CVE-2013-0214.html">Announcement</a>
783         </td>
784     </tr>
785
786     <tr>
787         <td>15 Jan 2013</td>
788         <td><a href="/samba/ftp/patches/security/samba-4.0.0-CVE-2013-0172.patch">
789         patch for Samba 4.0.0</a>
790         <td>Samba 4.0 as an AD DC may provide authenticated users with write
791         access to LDAP directory objects.</td>
792         <td>4.0.0</td>
793         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0172">CVE-2013-0172</a></td>
794         <td><a href="/samba/security/CVE-2013-0172.html">Announcement</a></td>
795     </tr>
796
797     <tr>
798         <td>30 Apr 2012</td>
799         <td><a href="/samba/ftp/patches/security/samba-3.4.16-CVE-2012-2111.patch">
800         patch for Samba 3.4.16</a><br />
801         <a href="/samba/ftp/patches/security/samba-3.5.14-CVE-2012-2111.patch">
802         patch for Samba 3.5.14</a><br />
803         <a href="/samba/ftp/patches/security/samba-3.6.4-CVE-2012-2111.patch">
804         patch for Samba 3.6.4</a><br />
805         <td>Incorrect permission checks when granting/removing privileges can
806         compromise file server security.</td>
807         <td>3.4.x-3.6.4</td>
808         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2111">CVE-2012-2111</a></td>
809         <td><a href="/samba/security/CVE-2012-2111.html">Announcement</a></td>
810     </tr>
811
812     <tr>
813         <td>10 Apr 2012</td>
814         <td><a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2012-1182.patch">
815         patch for Samba 3.0.37</a><br />
816         <a href="/samba/ftp/patches/security/samba-3.2.15-CVE-2012-1182.patch">
817         patch for Samba 3.2.15</a><br />
818         <a href="/samba/ftp/patches/security/samba-3.3.16-CVE-2012-1182.patch">
819         patch for Samba 3.3.16</a><br />
820         <a href="/samba/ftp/patches/security/samba-3.4.15-CVE-2012-1182.patch">
821         patch for Samba 3.4.15</a><br />
822         <a href="/samba/ftp/patches/security/samba-3.5.13-CVE-2012-1182.patch">
823         patch for Samba 3.5.13</a><br />
824         <a href="/samba/ftp/patches/security/samba-3.6.3-CVE-2012-1182.patch">
825         patch for Samba 3.6.3</a><br />
826         <td>"root" credential remote code execution</td>
827         <td>all current releases</td>
828         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1182">CVE-2012-1182</a></td>
829         <td><a href="/samba/security/CVE-2012-1182.html">Announcement</a></td>
830     </tr>
831
832     <tr>
833         <td>23 Feb 2012</td>
834         <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2012-0870.patch">
835         patch for Samba 3.0</a><br />
836         <a href="/samba/ftp/patches/security/samba-3.2-CVE-2012-0870.patch">
837         patch for Samba 3.2</a><br />
838         <a href="/samba/ftp/patches/security/samba-3.3-CVE-2012-0870.patch">
839         patch for Samba 3.3</a><br />
840         <td>Remote code execution vulnerability in smbd</td>
841         <td>pre-3.4</td>
842         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0870">CVE-2012-0870</a></td>
843         <td><a href="/samba/security/CVE-2012-0870.html">Announcement</a></td>
844     </tr>
845
846     <tr>
847         <td>29 Jan 2012</td>
848         <td><a href="/samba/ftp/patches/security/samba-3.6.2-CVE-2012-0817.patch">
849         patch for Samba 3.6.2</a>
850         <td>Memory leak/Denial of service</td>
851         <td>3.6.0-3.6.2</td>
852         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0817">CVE-2012-0817</a></td>
853         <td><a href="/samba/security/CVE-2012-0817.html">Announcement</a></td>
854     </tr>
855
856     <tr>
857         <td>26 Jul 2011</td>
858         <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2522.patch">
859         patch for Samba 3.3.15</a><br />
860         <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2522.patch">
861         patch for Samba 3.4.13</a><br />
862         <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2522.patch">
863         patch for Samba 3.5.9</a><br />
864         <td>Cross-Site Request Forgery in SWAT</td>
865         <td>all current releases</td>
866         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2522">CVE-2011-2522</a></td>
867         <td><a href="/samba/security/CVE-2011-2522.html">Announcement</a></td>
868     </tr>
869
870     <tr>
871         <td>26 Jul 2011</td>
872         <td><a href="/samba/ftp/patches/security/samba-3.3.15-CVE-2011-2694.patch">
873         patch for Samba 3.3.15</a><br />
874         <a href="/samba/ftp/patches/security/samba-3.4.13-CVE-2011-2694.patch">
875         patch for Samba 3.4.13</a><br />
876         <a href="/samba/ftp/patches/security/samba-3.5.9-CVE-2011-2694.patch">
877         patch for Samba 3.5.9</a><br />
878         <td>Cross-Site Scripting vulnerability in SWAT</td>
879         <td>all current releases</td>
880         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2694">CVE-2011-2694</a></td>
881         <td><a href="/samba/security/CVE-2011-2694.html">Announcement</a></td>
882     </tr>
883
884     <tr>
885         <td>18 Feb 2011</td>
886         <td><a href="/samba/ftp/patches/security/samba-3.3.14-CVE-2011-0719.patch">
887         patch for Samba 3.3.14</a><br />
888         <a href="/samba/ftp/patches/security/samba-3.4.11-CVE-2011-0719.patch">
889         patch for Samba 3.4.11</a><br />
890         <a href="/samba/ftp/patches/security/samba-3.5.6-CVE-2011-0719.patch">
891         patch for Samba 3.5.6</a><br />
892         <td>Denial of service - memory corruption</td>
893         <td>all current releases</td>
894         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0719">CVE-2011-0719</a></td>
895         <td><a href="/samba/security/CVE-2011-0719.html">Announcement</a></td>
896     </tr>
897
898     <tr>
899         <td>14 Sep 2010</td>
900         <td><a href="/samba/ftp/patches/security/samba-3.3.13-CVE-2010-3069.patch">
901         patch for Samba 3.3.13</a><br />
902         <a href="/samba/ftp/patches/security/samba-3.4.8-CVE-2010-3069.patch">
903         patch for Samba 3.4.8</a><br />
904         <a href="/samba/ftp/patches/security/samba-3.5.4-CVE-2010-3069.patch">
905         patch for Samba 3.5.4</a><br />
906         <td>Buffer Overrun Vulnerability</td>
907         <td>all current releases</td>
908         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3069">CVE-2010-3069</a></td>
909         <td><a href="/samba/security/CVE-2010-3069.html">Announcement</a></td>
910     </tr>
911
912     <tr>
913         <td>16 Jun 2010</td>
914         <td><a href="/samba/ftp/patches/security/samba-3.3.12-CVE-2010-2063.patch">
915         patch for Samba 3.3.12 and 3.2.15</a><br />
916         <a href="/samba/ftp/patches/security/samba-3.0.37-CVE-2010-2063.patch">
917         patch for Samba 3.0.37</a><br />
918         <td>Memory Corruption Vulnerability</td>
919         <td>3.0.x, 3.2.x, 3.3.0-3.3.12</td>
920         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-CVE-2010-2063">CVE-2010-2063</a></td>
921         <td><a href="/samba/security/CVE-2010-2063.html">Announcement</a></td>
922     </tr>
923
924     <tr>
925         <td>08 Mar 2010</td>
926         <td><a href="/samba/ftp/patches/security/samba-3.5.0-CVE-2010-0728.patch">
927         patch for Samba 3.5.0</a><br />
928         <a href="/samba/ftp/patches/security/samba-3.4.6-CVE-2010-0728.patch">
929         patch for Samba 3.4.6</a><br />
930         <a href="/samba/ftp/patches/security/samba-3.3.11-CVE-2010-0728.patch">
931         patch for Samba 3.3.11</a><br />
932         <td>Permission ignored</td>
933         <td>3.3.11, 3.4.6, 3.5.0</td>
934         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0728">CVE-2010-0728</a></td>
935         <td><a href="/samba/security/CVE-2010-0728.html">Announcement</a></td>
936     </tr>
937
938     <tr>
939         <td>02 Feb 2010</td>
940                   <td>not available</td>
941         <td>Change parameter "wide links" to default to "no"</td>
942         <td>pre-3.4.6</td>
943         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0926">CVE-2010-0926</a></td>
944         <td><a href="/samba/security/CVE-2010-0926.html">Announcement</a></td>
945     </tr>
946
947     <tr>
948         <td>01 Oct 2009</td>
949         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-1.patch">
950         patch 1 for Samba 3.4.1</a>
951         <a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2948-2.patch">
952         patch 2 for Samba 3.4.1</a>
953         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-1.patch">
954         patch 1 for Samba 3.3.7</a>
955         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2948-2.patch">
956         patch 2 for Samba 3.3.7</a>
957         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-1.patch">
958         patch 1 for Samba 3.2.14</a>
959         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2948-2.patch">
960         patch 2 for Samba 3.2.14</a>
961         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-1.patch">
962         patch 1 for Samba 3.0.36</a>
963         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2948-2.patch">
964         patch 2 for Samba 3.0.36</a>
965         <td>Information disclosure by setuid mount.cifs</td>
966         <td>all releases</td>
967         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2948</a></td>
968         <td><a href="/samba/security/CVE-2009-2948.html">Announcement</a></td>
969     </tr>
970
971     <tr>
972         <td>01 Oct 2009</td>
973         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2906.patch">
974         patch for Samba 3.4.1</a><br />
975         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2906.patch">
976         patch for Samba 3.3.7</a><br />
977         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2906.patch">
978         patch for Samba 3.2.14</a><br />
979         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2906.patch">
980         patch for Samba 3.0.36</a><br />
981         <td>Remote DoS against smbd on authenticated connections</td>
982         <td>all releases</td>
983         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906">CVE-2009-2906</a></td>
984         <td><a href="/samba/security/CVE-2009-2906.html">Announcement</a></td>
985     </tr>
986     <tr>
987
988     <tr>
989         <td>01 Oct 2009</td>
990         <td><a href="/samba/ftp/patches/security/samba-3.4.1-CVE-2009-2813.patch">
991         patch for Samba 3.4.1</a><br />
992         <a href="/samba/ftp/patches/security/samba-3.3.7-CVE-2009-2813.patch">
993         patch for Samba 3.3.7</a><br />
994         <a href="/samba/ftp/patches/security/samba-3.2.14-CVE-2009-2813.patch">
995         patch for Samba 3.2.14</a><br />
996         <a href="/samba/ftp/patches/security/samba-3.0.36-CVE-2009-2813.patch">
997         patch for Samba 3.0.36</a><br />
998         <td>Misconfigured /etc/passwd file may share folders unexpectedly</td>
999         <td>&gt; 3.0.11</td>
1000         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813">CVE-2009-2813</a></td>
1001         <td><a href="/samba/security/CVE-2009-2813.html">Announcement</a></td>
1002     </tr>
1003     <tr>
1004
1005     <tr>
1006         <td>23 Jun 2009</td>
1007         <td><a href="/samba/ftp/patches/security/samba-3.3.5-CVE-2009-1888.patch">
1008         patch for Samba 3.3.5</a><br />
1009         <a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1888.patch">
1010         patch for Samba 3.2.12</a><br />
1011         <a href="/samba/ftp/patches/security/samba-3.0.34-CVE-2009-1888.patch">
1012         patch for Samba 3.0.34</a><br />
1013         <td>Uninitialized read of a data value</td>
1014         <td>Samba 3.0.31 - 3.3.5</td>
1015         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888">CVE-2009-1888</a></td>
1016         <td><a href="/samba/security/CVE-2009-1888.html">Announcement</a></td>
1017     </tr>
1018     <tr>
1019
1020     <tr>
1021         <td>23 Jun 2009</td>
1022         <td><a href="/samba/ftp/patches/security/samba-3.2.12-CVE-2009-1886.patch">
1023         patch for Samba 3.2.12</a>
1024         <td>Formatstring vulnerability in smbclient</td>
1025         <td>Samba 3.2.0 - 3.2.12</td>
1026         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886">CVE-2009-1886</a></td>
1027         <td><a href="/samba/security/CVE-2009-1886.html">Announcement</a></td>
1028     </tr>
1029     <tr>
1030
1031     <tr>
1032         <td>05 Jan 2009</td>
1033         <td><a href="/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch">
1034         patch for Samba 3.2.6</a>
1035         <td>Potential access to "/" in setups with registry shares enabled</td>
1036         <td>Samba 3.2.0 - 3.2.6</td>
1037         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0022">CVE-2009-0022</a></td>
1038         <td><a href="/samba/security/CVE-2009-0022.html">Announcement</a></td>
1039     </tr>
1040     <tr>
1041         <td>27 Nov 2008</td>
1042         <td><a href="/samba/ftp/patches/security/samba-3.0.32-CVE-2008-4314.patch">
1043         patch for Samba 3.0.32</a>
1044         <a href="/samba/ftp/patches/security/samba-3.2.4-CVE-2008-4314.patch">
1045         patch for Samba 3.2.4</a></td>
1046         <td>Potential leak of arbitrary memory contents</td>
1047         <td>Samba 3.0.29 - 3.2.4</td>
1048         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4314">CVE-2008-4314</a></td>
1049         <td><a href="/samba/security/CVE-2008-4314.html">Announcement</a></td>
1050     </tr>
1051
1052     <tr>
1053         <td>27 Aug 2008</td>
1054         <td><a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-1.patch">
1055         patch 1 for Samba 3.2.2</a> 
1056         <a href="/samba/ftp/patches/security/samba-3.2.2-CVE-2008-3789-2.patch">
1057         patch 2 for Samba 3.2.2</a></td>
1058         <td>Wrong permissions of group_mapping.ldb</td>
1059         <td>Samba 3.2.0 - 3.2.2</td>
1060         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3789">CVE-2008-3789</a></td>
1061         <td><a href="/samba/security/CVE-2008-3789.html">Announcement</a></td>
1062     </tr>
1063
1064     <tr>
1065         <td>29 May 2008</td>
1066         <td><a href="/samba/ftp/patches/security/samba-3.0.29-CVE-2008-1105.patch">patch for Samba 3.0.29</a></td>
1067         <td>Boundary failure when parsing SMB responses</td>
1068         <td>Samba 3.0.0 - 3.0.29</td>
1069         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105">CVE-2008-1105</a></td>
1070         <td><a href="/samba/security/CVE-2008-1105.html">Announcement</a></td>
1071     </tr>
1072
1073     <tr>
1074         <td>10 Dec 2007</td>
1075         <td><a href="/samba/ftp/patches/security/samba-3.0.27a-CVE-2007-6015.patch">patch for Samba 3.0.27a</a></td>
1076         <td>Remote Code Execution in Samba's nmbd (send_mailslot())</td>
1077         <td>Samba 3.0.0 - 3.0.27a</td>
1078         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6015">CVE-2007-6015</a></td>
1079         <td><a href="/samba/security/CVE-2007-6015.html">Announcement</a></td>
1080     </tr>
1081
1082     <tr>
1083         <td>15 Nov 2007</td>
1084         <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-5398.patch">patch for Samba 3.0.26a</a></td>
1085         <td>Remote Code Execution in Samba's nmbd</td>
1086         <td>Samba 3.0.0 - 3.0.26a</td>
1087         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398">CVE-2007-5398</a></td>
1088         <td><a href="/samba/security/CVE-2007-5398.html">Announcement</a></td>
1089     </tr>
1090
1091     <tr>
1092         <td>15 Nov 2007</td>
1093         <td><a href="/samba/ftp/patches/security/samba-3.0.26a-CVE-2007-4572.patch">patch for Samba 3.0.26a</a></td>
1094         <td>GETDC mailslot processing buffer overrun in nmbd</td>
1095         <td>Samba 3.0.0 - 3.0.26a</td>
1096         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4572">CVE-2007-4572</a></td>
1097         <td><a href="/samba/security/CVE-2007-4572.html">Announcement</a></td>
1098     </tr>
1099
1100     <tr>
1101         <td>11 Sep 2007</td>
1102         <td><a href="/samba/ftp/patches/security/samba-3.0.25-CVE-2007-4138.patch">patch for Samba 3.0.25</a></td>
1103         <td>Incorrect primary group assignment for users using the rfc2307 or sfu nss info plugin.</td>
1104         <td>Samba 3.0.25 - 3.0.25c</td>
1105         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4138">CVE-2007-4138</a></td>
1106         <td><a href="/samba/security/CVE-2007-4138.html">Announcement</a></td>
1107     </tr>
1108
1109     <tr>
1110         <td>14 May 2007</td>
1111         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2447_v2.patch">patch for Samba 3.0.24</a></td>
1112         <td>Remote Command Injection Vulnerability (Updated June 5 to include missing &quot;c&quot; character from INCLUDE list).</td>
1113         <td>Samba 3.0.0 - 3.0.25rc3</td>
1114         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2447">CVE-2007-2447</a></td>
1115         <td><a href="/samba/security/CVE-2007-2447.html">Announcement</a></td>
1116     </tr>
1117
1118     <tr>
1119         <td>14 May 2007</td>
1120         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2446_v2.patch">patch for Samba 3.0.24</a></td>
1121         <td>Multiple Heap Overflows Allow Remote Code Execution (Updated May 25 to fix regression in Samba domain controller logon code).</td>
1122         <td>Samba 3.0.0 - 3.0.25rc3</td>
1123         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2446">CVE-2007-2446</a></td>
1124         <td><a href="/samba/security/CVE-2007-2446.html">Announcement</a></td>
1125     </tr>
1126
1127     <tr>
1128         <td>14 May 2007</td>
1129         <td><a href="/samba/ftp/patches/security/samba-3.0.24-CVE-2007-2444_v2.patch">patch for Samba 3.0.24</a></td>
1130         <td>Local SID/Name translation bug can result in user privilege elevation (Updated May 25 to fix regression in the &quot;force group&quot; parameter).</td>
1131         <td>Samba 3.0.23d - 3.0.25pre2</td>
1132         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2444">CVE-2007-2444</a></td>
1133         <td><a href="/samba/security/CVE-2007-2444.html">Announcement</a></td>
1134     </tr>
1135
1136     <tr>
1137         <td>5 Feb 2007</td>
1138         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0452.patch">patch for Samba 3.0.23d</a></td>
1139         <td>Potential Denial of Service bug in smbd</td>
1140         <td>Samba 3.0.6 - 3.0.23d</td>
1141         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452">CVE-2007-0452</a></td>
1142         <td><a href="/samba/security/CVE-2007-0452.html">Announcement</a></td>
1143     </tr>
1144
1145     <tr>
1146         <td>5 Feb 2007</td>
1147         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0453.patch">patch for Samba 3.0.23d</a></td>
1148         <td>Buffer overrun in NSS host lookup Winbind library on Solaris</td>
1149         <td>Samba 3.0.21 - 3.0.23d</td>
1150         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0453">CVE-2007-0453</a></td>
1151         <td><a href="/samba/security/CVE-2007-0453.html">Announcement</a></td>
1152     </tr>
1153
1154     <tr>
1155         <td>5 Feb 2007</td>
1156         <td><a href="/samba/ftp/patches/security/samba-3.0.23d-CVE-2007-0454.patch">patch for Samba 3.0.23d</a></td>
1157         <td>Format string bug in afsacl.so VFS plugin</td>
1158         <td>Samba 3.0.6 - 3.0.23d</td>
1159         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0454">CVE-2007-0454</a></td>
1160         <td><a href="/samba/security/CVE-2007-0454.html">Announcement</a></td>
1161     </tr>
1162
1163     <tr>
1164         <td>10 July 2006</td>
1165         <td><a href="/samba/ftp/patches/security/samba-3.0-CVE-2006-3403.patch">patch for Samba 3.0.1 - 3.0.22</a></td>
1166         <td>Memory exhaustion DoS against smbd</td>
1167         <td>Samba 3.0.1 - 3.0.22</td>
1168         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3403">CVE-2006-3403</a></td>
1169         <td><a href="/samba/security/CVE-2006-3403.html">Announcement</a></td>
1170     </tr>
1171
1172     <tr>
1173     <tr>
1174         <td>30 March 2006</td>
1175         <td><a href="/samba/ftp/patches/security/samba-3.0.21-CVE-2006-1059.patch">patch for Samba 3.0.21[a-c]</a></td>
1176         <td>Exposure of machine account credentials in winbind log files</td>
1177         <td>Samba 3.0.21 - 3.0.21c</td>
1178         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1059">CVE-2006-1059</a></td>
1179         <td><a href="/samba/security/CVE-2006-1059.html">Announcement</a></td>
1180     </tr>
1181
1182     <tr>
1183         <td>16 December 2004</td>
1184         <td><a href="/samba/ftp/patches/security/samba-3.0.9-CVE-2004-1154.patch">patch for Samba 3.0.9</a></td>
1185         <td>Integer Overflow in security descriptor parsing</td>
1186         <td>Samba 2.x, 3.0.x &lt;&#61; 3.0.9</td>
1187         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154">CVE-2004-1154</a></td>
1188         <td><a href="/samba/security/CVE-2004-1154.html">Announcement</a></td>
1189     </tr>    
1190
1191     <tr>
1192     <tr>
1193         <td>15 November 2004</td>
1194         <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0882.patch">patch for &lt;&#61;Samba 3.0.7</a></td>
1195         <td>Buffer Overrun in smbd</td>
1196         <td>Samba 3.0.x &lt;&#61; 3.0.7</td>
1197         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0882">CVE-2004-0882</a></td>
1198         <td><a href="/samba/security/CVE-2004-0882.html">Announcement</a></td>
1199     </tr>    
1200
1201     <tr>
1202         <td>8 November 2004</td>
1203         <td><a href="/samba/ftp/patches/security/samba-3.0.7-CVE-2004-0930.patch">patch for &lt;&#61;Samba 3.0.7</a></td>
1204         <td>Remote DoS</td>
1205         <td>Samba 3.0.x &lt;&#61; 3.0.7</td>
1206         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0930">CVE-2004-0930</a></td>
1207         <td><a href="/samba/security/CVE-2004-0930.html">Announcement</a></td>
1208     </tr>    
1209
1210     <tr>
1211         <td>30 September 2004</td>
1212         <td><a href="/samba/ftp/stable/samba-2.2.12.tar.gz">Samba 2.2.12</a> and/or  <a href="/samba/ftp/patches/security/samba-3.0.2a-reduce_name.patch">patch for &lt;&#61;Samba 3.0.2a</a></td>
1213         <td>Potential arbitrary file access</td>
1214         <td>Samba 2.2.x &lt;&#61;2.2.11 and Samba 3.0.x &lt;&#61;3.0.2a</td>
1215         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0815">CVE-2004-0815</a></td>
1216         <td><a href="/samba/security/CVE-2004-0815.html">Announcement</a></td>
1217     </tr>    
1218         
1219       
1220       <tr>
1221         <td>13 Sept 2004</td>
1222         <td><a href="/samba/ftp/patches/security/samba-3.0.5-DoS.patch">3.0.5 patch</a></td>
1223         <td>Two DoS bugs; one affecting smbd, the other nmbd.</td>
1224         <td>3.0.x &lt;= 3.0.6</td>
1225         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0807">CVE-2004-0807</a>, <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0808">CVE-2004-0808</a></td>
1226         <td><a href="/samba/security/CVE-2004-0807_CVE-2004-0808.html">Announcement</a></td>
1227       </tr>
1228       
1229       <tr>
1230         <td>22 Jul 2004</td>
1231         <td><a href="/samba/ftp/stable/samba-3.0.5.tar.gz">3.0.5</a></td>
1232         <td>Two potential buffer overruns</td>
1233         <td>>=3.0.2</td>
1234         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0600">CVE-2004-0600</a>, 
1235             <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1236         </td>
1237         <td><a href="/samba/security/CVE-2004-0600.html">CVE-2004-0600 Announcement</a>
1238             <a href="/samba/security/CVE-2004-0686.html">CVE-2004-0686 Announcement</a></td>
1239       </tr>
1240       
1241       <tr>
1242         <td>22 Jul 2004</td>
1243         <td><a href="/samba/ftp/stable/samba-2.2.10.tar.gz">2.2.10</a></td>
1244         <td>Buffer overrun in hash mangling method</td>
1245         <td>all 2.2 releases</td>
1246         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0686">CVE-2004-0686</a>
1247         </td>
1248         <td><a href="/samba/history/samba-2.2.10.html">release notes</a></td>
1249       </tr>
1250       
1251       <tr>
1252         <td>9 Feb 2004</td>
1253         <td><a href="/samba/ftp/old-versions/samba-3.0.2a.tar.gz">3.0.2a</a></td>
1254         <td align="left">Password initialization bug that could grant
1255         an attacker unauthorized
1256         access to a user account created by the mksmbpasswd.sh shell script.</td>
1257         <td>>=3.0.0</td>
1258         <td><a
1259         href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0082">CVE-2004-0082</a></td>
1260         <td><a href="/samba/security/CVE-2004-0082.html">Announcement</a></td>
1261       </tr>
1262       
1263       <tr>
1264         <td>7 Apr 2003</td>
1265         <td><a href="/samba/ftp/old-versions/samba-2.2.8a.tar.gz">2.2.8a</a></td>
1266         <td>Buffer overrun condition in the SMB/CIFS packet fragment
1267         re-assembly code.</td>
1268         <td>all 2.0 releases and <= 2.2.8</td>
1269         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0196">CVE-2003-0196</a>,
1270         <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201">CVE-2003-0201</a></td>
1271         <td><a href="/samba/history/samba-2.2.8a.html">release notes</a></td>
1272       </tr>
1273       
1274       <tr>
1275         <td>10 Dec 2002</td>
1276         <td><a href="/samba/ftp/old-versions/samba-2.2.7a.tar.gz">2.2.7a</a></td>
1277         <td>Bug in the length checking for encrypted password change
1278         requests from clients.</td>
1279         <td>2.2.2 - 2.2.6</td>
1280         <td><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0085">CVE-2003-0085</a></td>
1281         <td><a href="/samba/history/samba-2.2.7a.html">release notes</a></td>
1282       </tr>
1283       
1284       <tr>
1285         <td>23 Jun 2001</td>
1286         <td><a href="/samba/ftp/old-versions/samba-2.2.0a.tar.gz">2.2.0a</a></td>
1287         <td>Bug in expansion of certain smb.conf variables such as 
1288         %m that could grant an attacker the capability to overwrite arbitrary 
1289         files on the server.  Bug that causes smbd not to honor the hosts allow 
1290         and deny smb.conf directives.</td>
1291         <td>2.2.0</td>
1292         <td>&nbsp</td>
1293         <td><a href="/samba/history/samba-2.2.0a.html">release notes</a></td>
1294       </tr>
1295       
1296       <tr>
1297         <td>23 Jun 2001</td>
1298         <td><a href="/samba/ftp/old-versions/samba-2.0.10.tar.gz">2.0.10</a></td>
1299         <td>Bug in the handling of temporary files that allows local 
1300         users to destroy data on local devices.</td>
1301         <td>>= 2.0.0</td>
1302         <td>&nbsp</td>
1303         <td><a href="/samba/history/samba-2.0.10.html">release notes</a></td>
1304       </tr>
1305                 
1306     </table>
1307     
1308     <p><em>If you suspect you have discovered a serious security hole in a
1309 Samba release, please send an email to <a
1310 href="mailto:security@samba.org">security@samba.org</a>.</em></p>
1311
1312 <!--#include virtual="footer_history.html" -->