-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 02 Sep 2019 15:39:42 +0200 Source: samba Architecture: source Version: 2:4.9.5+dfsg-5+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Samba Maintainers <pkg-samba-ma...@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <car...@debian.org> Changes: samba (2:4.9.5+dfsg-5+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * gbp.conf: change debian-branch to buster-security, and merge-mode to merge * CVE-2019-10197: smbd: separate out impersonation debug info into a new function. * CVE-2019-10197: smbd: make sure that change_to_user_internal() always resets current_user.done_chdir. * CVE-2019-10197: smbd: make sure we reset current_user.{need,done}_chdir in become_root() * CVE-2019-10197: selftest: make fsrvp_share its own independent subdirectory. * CVE-2019-10197: test_smbclient_s3.sh: add regression test for the no permission on share root problem. * CVE-2019-10197: smbd: split change_to_user_impersonate() out of change_to_user_internal() Checksums-Sha1: d6563cbda7fbbf9ce3c3caf579cd770d2eda88e5 4316 samba_4.9.5+dfsg-5+deb10u1.dsc 30c5d848ceab158f8b75322319cea678ad69db58 11415312 samba_4.9.5+dfsg.orig.tar.xz 920d63342790d30c5a1c63e931b71af6ee1e0382 251948 samba_4.9.5+dfsg-5+deb10u1.debian.tar.xz Checksums-Sha256: 1b2586cb05d57a2d6c2b67e538d77da2c1615c5889f2fda5cd1f3cadaf761042 4316 samba_4.9.5+dfsg-5+deb10u1.dsc bdb37b64ebe0c891d59a859c9b7e81539fd71fbb59146013896e97cbfb8b39ae 11415312 samba_4.9.5+dfsg.orig.tar.xz d44dac430bbaf6ef860d783924a8c5297a94d27783e83c321eb1d698a277dc97 251948 samba_4.9.5+dfsg-5+deb10u1.debian.tar.xz Files: 16a543cae3a9e1de73205bb9e601291a 4316 net optional samba_4.9.5+dfsg-5+deb10u1.dsc d272a334fba5804302e7344a289231bf 11415312 net optional samba_4.9.5+dfsg.orig.tar.xz ee86f239a9438589bd91831d97951241 251948 net optional samba_4.9.5+dfsg-5+deb10u1.debian.tar.xz
-----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl1tIr5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EdlgP/1I6gKlXwHWZmXwXqMKi04ce5Plrf5RN ntUmB8FHCeNVE2d7Il1Vr0v6GOpeWCyHkc15NSZtX+uVsk8RG/Lj8jzNi1wio+g6 FrBcU71VlJPA5Z0b+mCAKwXYtbKJ3JEgEYvBw+lRXnMAWsKMyOf0YF6v0TmmYJ47 oRr7qzfKW1w13+F/fcHP9cNUaiRMIWN1MgMSiCvMVewqovWrCFDgsvW44GJnQuTN fTR5sBocjgz84qOrvx28wxKqJWmwr4/VxUKoMgQtNulT9gLxx1/8ExbfniSkyhRz kE/szzqqQS4rqVulCtGpk9sKOpnk6SSikIb1gFN7etOymZn3TJ8MbLvfNcOFYsnP woQVGepYQ2rbpT/fEhTn3/5Xv4qYU0eEpPbfEatqY0eSxkHMesQrqFk0NgJ4us85 L0cioa11a4U62Oih3eJrpnYKreelsQ3PzGROIecFP0yjn/0GTfIJrezUozW/aidG jVD4ZnN4Z/L01Pjc2J93YFFB1aEZVMg/kHFi9GU/2gpV8hiiagLdKnVL90zATg/C z80hv65S2SpFslE48q6KNryj0u9vAkW5ipHoT9EobB1a2w9FGKTXVOtbyNrcE9yH MeUIBbNOECxFbn6PnOxrAq6eMkAUGlJWKaK8dnDJjXarZwYJFsbq/cRhFpMJKWPD XD1nSUgveb5L =VmIg -----END PGP SIGNATURE-----