Fedora Linux 8567 Published by

A cifs-utils security update has been released for Fedora 32.



SECURITY: Fedora 32 Update: cifs-utils-6.11-1.fc32


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2020-cfdd73f1b4
2020-11-11 01:19:50.943659
--------------------------------------------------------------------------------

Name : cifs-utils
Product : Fedora 32
Version : 6.11
Release : 1.fc32
URL :   http://linux-cifs.samba.org/cifs-utils/
Summary : Utilities for mounting and managing CIFS mounts
Description :
The SMB/CIFS protocol is a standard file sharing protocol widely deployed
on Microsoft Windows machines. This package contains tools for mounting
shares on Linux using the SMB/CIFS protocol. The tools in this package
work in conjunction with support in the kernel to allow one to mount a
SMB/CIFS share onto a client and use it as if it were a standard Linux
file system.

--------------------------------------------------------------------------------
Update Information:

New upstream release: - fixes CVE-2020-14342 cifs-utils: shell command
injection in mount.cifs - adds `smb2-quota` tool - adds `mount.smb3` as a
symlink to `mount.cifs`
--------------------------------------------------------------------------------
ChangeLog:

* Mon Nov 2 2020 Alexander Bokovoy - 6.11-1
- Update to v6.11 release
- Resolves: rhbz#1876400 - CVE-2020-14342 - cifs-utils: shell command injection
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1784578 - cifs-utils-6.11 is available
  https://bugzilla.redhat.com/show_bug.cgi?id=1784578
[ 2 ] Bug #1876400 - CVE-2020-14342 cifs-utils: shell command injection in mount.cifs [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1876400
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-cfdd73f1b4' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys