[3.6] samba: Remote code execution from a writable share (CVE-2017-7494)
All versions of Samba from 3.5.0 onwards are vulnerable to a remote
code execution vulnerability, allowing a malicious client to upload a
shared library to a writable share, and then cause the server to load
and execute it.
Samba 4.6.4, 4.5.10 and 4.4.14 have been issued as
security releases to correct the defect.
References:
https://www.samba.org/samba/security/CVE-2017-7494.html
https://www.samba.org/samba/history/security.html
(from redmine: issue id 7320, created on 2017-05-25, closed on 2017-05-25)
- Relations:
- parent #7319 (closed)
- Changesets:
- Revision c5b93ddc by Natanael Copa on 2017-05-25T10:01:18Z:
main/samba: security upgrade to 4.6.4 (CVE-2017-7494)
fixes #7320