SECURITY: Fedora 32 Update: cifs-utils-6.11-1.fc32
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2020-cfdd73f1b4
2020-11-11 01:19:50.943659
--------------------------------------------------------------------------------
Name : cifs-utils
Product : Fedora 32
Version : 6.11
Release : 1.fc32
URL : http://linux-cifs.samba.org/cifs-utils/
Summary : Utilities for mounting and managing CIFS mounts
Description :
The SMB/CIFS protocol is a standard file sharing protocol widely deployed
on Microsoft Windows machines. This package contains tools for mounting
shares on Linux using the SMB/CIFS protocol. The tools in this package
work in conjunction with support in the kernel to allow one to mount a
SMB/CIFS share onto a client and use it as if it were a standard Linux
file system.
--------------------------------------------------------------------------------
Update Information:
New upstream release: - fixes CVE-2020-14342 cifs-utils: shell command
injection in mount.cifs - adds `smb2-quota` tool - adds `mount.smb3` as a
symlink to `mount.cifs`
--------------------------------------------------------------------------------
ChangeLog:
* Mon Nov 2 2020 Alexander Bokovoy - 6.11-1
- Update to v6.11 release
- Resolves: rhbz#1876400 - CVE-2020-14342 - cifs-utils: shell command injection
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1784578 - cifs-utils-6.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1784578
[ 2 ] Bug #1876400 - CVE-2020-14342 cifs-utils: shell command injection in mount.cifs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1876400
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-cfdd73f1b4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
A cifs-utils security update has been released for Fedora 32.