Bug 95325 - [MAINTAINER] Security update of net/samba3 to 3.0.22
Summary: [MAINTAINER] Security update of net/samba3 to 3.0.22
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Marcus Alves Grando
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-04-05 02:10 UTC by Timur I. Bakeyev
Modified: 2006-04-05 04:14 UTC (History)
0 users

See Also:


Attachments
samba3.diff (7.96 KB, patch)
2006-04-05 02:10 UTC, Timur I. Bakeyev
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Timur I. Bakeyev 2006-04-05 02:10:16 UTC

== Subject: Exposed clear text of domain machine
== account password in debug logs (log
== level >= 5)
== CVE ID#: CAN_2006-1059
==
== Versions: Samba Samba 3.0.21 - 3.0.21c (inclusive)
==
== Summary: The winbindd daemon writes the clear text
== of the machine trust account password to
== log files. These log files are world
== readable by default.
Comment 1 Marcus Alves Grando freebsd_committer freebsd_triage 2006-04-05 03:07:22 UTC
Responsible Changed
From-To: freebsd-ports-bugs->mnag

I'll take it.
Comment 2 Marcus Alves Grando freebsd_committer freebsd_triage 2006-04-05 04:14:35 UTC
State Changed
From-To: open->closed

Committed. Thanks!