Opened 4 weeks ago

Closed 3 weeks ago

#19554 closed enhancement (fixed)

samba-4.20.0 (and add --with-system-mitkrb5, recommend krb5 dependency)

Reported by: Bruce Dubbs Owned by: Rahul Chandra
Priority: elevated Milestone: 12.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New minor version.

Change History (10)

comment:1 by Rahul Chandra, 4 weeks ago

Owner: changed from blfs-book to Rahul Chandra
Status: newassigned

comment:3 by Rahul Chandra, 4 weeks ago

It mentions CVE-2022-37967 because it is forcing samba to be built with a newer version of Kerberos. I don't think this needs a new Security Advisory as even current versions of Samba built against mitkrb 1.21.X have the fix.

comment:4 by Tim Tassonis, 4 weeks ago

Any news here?

comment:5 by Tim Tassonis, 4 weeks ago

Seems, it needs a system kerberos. I only got the client libs (krb5 and gssapi), is that not enough?

in reply to:  3 comment:6 by Xi Ruoyao, 4 weeks ago

Priority: normalelevated

Replying to Rahul Chandra:

It mentions CVE-2022-37967 because it is forcing samba to be built with a newer version of Kerberos. I don't think this needs a new Security Advisory as even current versions of Samba built against mitkrb 1.21.X have the fix.

Oops, it's building an internal copy of krb5 w/o --with-system-mitkrb5 so we are vulnerable.

I'd suggest to add --with-system-mitkrb5 into the book and raise krb5 to recommended (it will also save some building time). It works for me but not Tim (see the blfs-dev discuss, let's wait for Tim's response).

comment:7 by Xi Ruoyao, 4 weeks ago

Summary: samba-4.20.0samba-4.20.0 (and add --with-system-mitkrb5, recommend krb5 dependency)

comment:8 by Tim Tassonis, 4 weeks ago

OK, I can happily confirm that, after fixing my MIT Kerberos V5 build, I now successfully built samba 4.20.0 against it.

I have not made any extensive tests, but a very simple server runs and the smbclient cann connect to it.

comment:9 by Tim Tassonis, 4 weeks ago

Gonna build and install it now on my main (private) LDAP based Fileserver/Torrent Download Directory and use it a little, can always revert.

comment:10 by Rahul Chandra, 3 weeks ago

Resolution: fixed
Status: assignedclosed
Fixed @
2a406a80d09225e7b9f316a1dcfe0dd881d0e74c - Update to node.js-20.12.1
995d8944b59459835ce51e65dfd10573c3a7ad75 - Update to samba-4.20.0
b759af786bac343cff0d53b398c18eacdbbd0c72 - Update to mesa-24.0.4
Note: See TracTickets for help on using tickets.