<feed xmlns='http://www.w3.org/2005/Atom'>
<title>samba.git/lib, branch v3-5-test</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/'/>
<entry>
<title>lib/replace: replace all *printf function if we replace snprintf (bug #9390)</title>
<updated>2012-11-15T11:00:34+00:00</updated>
<author>
<name>Stefan Metzmacher</name>
<email>metze@samba.org</email>
</author>
<published>2012-11-13T13:07:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=05f151c041e407514c1b35619b2f2454aa4d614b'/>
<id>05f151c041e407514c1b35619b2f2454aa4d614b</id>
<content type='text'>
This fixes segfaults in log level = 10 on Solaris.

Signed-off-by: Stefan Metzmacher &lt;metze@samba.org&gt;
Signed-off-by: Björn Jacke &lt;bj@sernet.de&gt;

Autobuild-User(master): Björn Jacke &lt;bj@sernet.de&gt;
Autobuild-Date(master): Wed Nov 14 19:41:14 CET 2012 on sn-devel-104
(cherry picked from commit a15da3625850d97b3da1b02308c870f820007c52)

The last 5 patches address bug #9390 - Solaris printf doesn't allow %s, NULL.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This fixes segfaults in log level = 10 on Solaris.

Signed-off-by: Stefan Metzmacher &lt;metze@samba.org&gt;
Signed-off-by: Björn Jacke &lt;bj@sernet.de&gt;

Autobuild-User(master): Björn Jacke &lt;bj@sernet.de&gt;
Autobuild-Date(master): Wed Nov 14 19:41:14 CET 2012 on sn-devel-104
(cherry picked from commit a15da3625850d97b3da1b02308c870f820007c52)

The last 5 patches address bug #9390 - Solaris printf doesn't allow %s, NULL.
</pre>
</div>
</content>
</entry>
<entry>
<title>libreplace: Fix symbol names for snprintf/asprintf/vasprintf.</title>
<updated>2012-11-15T11:00:20+00:00</updated>
<author>
<name>Jelmer Vernooij</name>
<email>jelmer@samba.org</email>
</author>
<published>2012-05-13T01:21:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=27405fb8cfaa56f3a39cdcd2fd635fd37af629f9'/>
<id>27405fb8cfaa56f3a39cdcd2fd635fd37af629f9</id>
<content type='text'>
Autobuild-User: Jelmer Vernooij &lt;jelmer@samba.org&gt;
Autobuild-Date: Sun May 13 05:16:28 CEST 2012 on sn-devel-104
(cherry picked from commit cf67da70c9a63c4dc63f287059321d6c36d1e19e)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Autobuild-User: Jelmer Vernooij &lt;jelmer@samba.org&gt;
Autobuild-Date: Sun May 13 05:16:28 CEST 2012 on sn-devel-104
(cherry picked from commit cf67da70c9a63c4dc63f287059321d6c36d1e19e)
</pre>
</div>
</content>
</entry>
<entry>
<title>libreplace: fixed declaration of dprintf() on FreeBSD (cherry picked from commit a599319d0a389ff0c31dae8068cd7a78352aa9e7)</title>
<updated>2012-11-15T11:00:20+00:00</updated>
<author>
<name>Andrew Tridgell</name>
<email>tridge@freebsd.home.tridgell.net</email>
</author>
<published>2010-03-23T18:06:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=fa16d0e4c2329fad8edde5a5e8d626a90caba6d9'/>
<id>fa16d0e4c2329fad8edde5a5e8d626a90caba6d9</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>libreplace: added replacements for dprintf() and vdprintf()</title>
<updated>2012-11-15T11:00:20+00:00</updated>
<author>
<name>Andrew Tridgell</name>
<email>tridge@samba.org</email>
</author>
<published>2010-02-11T09:18:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=4bf8dc438318e06ee96dc1b6084dddd8700739e7'/>
<id>4bf8dc438318e06ee96dc1b6084dddd8700739e7</id>
<content type='text'>
these are very useful for writing files with formatted writes

Pair-Programmed-With: Andrew Bartlett &lt;abartlet@samba.org&gt;
(cherry picked from commit d6fb64c51244529388b1f79ba8220ff608e1e4de)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
these are very useful for writing files with formatted writes

Pair-Programmed-With: Andrew Bartlett &lt;abartlet@samba.org&gt;
(cherry picked from commit d6fb64c51244529388b1f79ba8220ff608e1e4de)
</pre>
</div>
</content>
</entry>
<entry>
<title>libreplace: some systems don't have memmem()</title>
<updated>2012-11-15T11:00:20+00:00</updated>
<author>
<name>Andrew Tridgell</name>
<email>tridge@samba.org</email>
</author>
<published>2010-01-01T23:01:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=42057793ebb3ccdc4e63f59753bca8dd677e9748'/>
<id>42057793ebb3ccdc4e63f59753bca8dd677e9748</id>
<content type='text'>
added rep_memmem() and a testsuite
(cherry picked from commit fef3c910da421e890925e5e61275fc457da87f6e)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
added rep_memmem() and a testsuite
(cherry picked from commit fef3c910da421e890925e5e61275fc457da87f6e)
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug 7462 - Non-standard SA_RESETHAND is used in ...lib/tevent/tevent_sig</title>
<updated>2011-08-02T18:49:46+00:00</updated>
<author>
<name>Jeremy Allison</name>
<email>jra@samba.org</email>
</author>
<published>2011-08-02T18:49:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=490986add9d5e80b24e90dbfe3e3ef23ce5584a0'/>
<id>490986add9d5e80b24e90dbfe3e3ef23ce5584a0</id>
<content type='text'>
Make SA_RESETHAND conditional on its existance.

Autobuild-User: Jeremy Allison &lt;jra@samba.org&gt;
Autobuild-Date: Mon Aug  1 22:03:45 CEST 2011 on sn-devel-104
(cherry picked from commit 0c67efdd68b9808542c090b9fd9920e4e37d85d0)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Make SA_RESETHAND conditional on its existance.

Autobuild-User: Jeremy Allison &lt;jra@samba.org&gt;
Autobuild-Date: Mon Aug  1 22:03:45 CEST 2011 on sn-devel-104
(cherry picked from commit 0c67efdd68b9808542c090b9fd9920e4e37d85d0)
</pre>
</div>
</content>
</entry>
<entry>
<title>libreplace: include sys/file.h only when available</title>
<updated>2011-06-17T19:01:19+00:00</updated>
<author>
<name>Björn Jacke</name>
<email>bj@sernet.de</email>
</author>
<published>2010-05-30T19:52:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=a33b6032beb45f7ba07432899236fccb133a6dfc'/>
<id>a33b6032beb45f7ba07432899236fccb133a6dfc</id>
<content type='text'>
thanks to Joachim Schmitz &lt;schmitz@hp.com&gt;. This fixes #7460.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
thanks to Joachim Schmitz &lt;schmitz@hp.com&gt;. This fixes #7460.
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix our asn.1 parser to handle negative numbers.</title>
<updated>2011-05-26T18:21:38+00:00</updated>
<author>
<name>Jeremy Allison</name>
<email>jra@samba.org</email>
</author>
<published>2011-05-24T19:47:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=d210395a50b5d5043bdcfb75f670f8abab91f974'/>
<id>d210395a50b5d5043bdcfb75f670f8abab91f974</id>
<content type='text'>
Autobuild-User: Jeremy Allison &lt;jra@samba.org&gt;
Autobuild-Date: Tue May 24 22:57:16 CEST 2011 on sn-devel-104
(cherry picked from commit e719dfd4dc178f001a5f804fb1ac4e587574415f)

Fix bug #8163 (asn.1 library does not correctly read negative integers).
(cherry picked from commit 859d13141cd831488b60e413f7141514ae4464b5)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Autobuild-User: Jeremy Allison &lt;jra@samba.org&gt;
Autobuild-Date: Tue May 24 22:57:16 CEST 2011 on sn-devel-104
(cherry picked from commit e719dfd4dc178f001a5f804fb1ac4e587574415f)

Fix bug #8163 (asn.1 library does not correctly read negative integers).
(cherry picked from commit 859d13141cd831488b60e413f7141514ae4464b5)
</pre>
</div>
</content>
</entry>
<entry>
<title>tdb_expand: limit the expansion with huge records</title>
<updated>2011-05-18T18:28:55+00:00</updated>
<author>
<name>Simo Sorce</name>
<email>idra@samba.org</email>
</author>
<published>2011-04-18T12:45:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=c8ba5d41f3c2ab25cb9b9d0fa78b4f884d4b9721'/>
<id>c8ba5d41f3c2ab25cb9b9d0fa78b4f884d4b9721</id>
<content type='text'>
ldb can create huge records when saving indexes.
Limit the tdb expansion to avoid consuming a lot of memory for
no good reason if the record being saved is huge.

Fix bug #7610 (winbindd_cache.tdb grows too large when scaled).
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
ldb can create huge records when saving indexes.
Limit the tdb expansion to avoid consuming a lot of memory for
no good reason if the record being saved is huge.

Fix bug #7610 (winbindd_cache.tdb grows too large when scaled).
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix denial of service - memory corruption.</title>
<updated>2011-02-28T13:43:59+00:00</updated>
<author>
<name>Jeremy Allison</name>
<email>jra@samba.org</email>
</author>
<published>2011-02-27T16:58:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=b9c9874cdddfde5726c985b2154adee47597f77f'/>
<id>b9c9874cdddfde5726c985b2154adee47597f77f</id>
<content type='text'>
CVE-2011-0719

Fix bug #7949 (DoS in Winbind and smbd with many file descriptors open).

All current released versions of Samba are vulnerable to
a denial of service caused by memory corruption. Range
checks on file descriptors being used in the FD_SET macro
were not present allowing stack corruption. This can cause
the Samba code to crash or to loop attempting to select
on a bad file descriptor set.

A connection to a file share, or a local account is needed
to exploit this problem, either authenticated or unauthenticated
(guest connection).

Currently we do not believe this flaw is exploitable
beyond a crash or causing the code to loop, but on the
advice of our security reviewers we are releasing fixes
in case an exploit is discovered at a later date.
(cherry picked from commit c3ad6eb506623435d3d9ce62d6f34ed1c960d4be)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
CVE-2011-0719

Fix bug #7949 (DoS in Winbind and smbd with many file descriptors open).

All current released versions of Samba are vulnerable to
a denial of service caused by memory corruption. Range
checks on file descriptors being used in the FD_SET macro
were not present allowing stack corruption. This can cause
the Samba code to crash or to loop attempting to select
on a bad file descriptor set.

A connection to a file share, or a local account is needed
to exploit this problem, either authenticated or unauthenticated
(guest connection).

Currently we do not believe this flaw is exploitable
beyond a crash or causing the code to loop, but on the
advice of our security reviewers we are releasing fixes
in case an exploit is discovered at a later date.
(cherry picked from commit c3ad6eb506623435d3d9ce62d6f34ed1c960d4be)
</pre>
</div>
</content>
</entry>
</feed>
