Samba has issued an advisory on April 8: https://www.samba.org/samba/security/CVE-2019-3880.html The patch to fix it is here: https://www.samba.org/samba/ftp/patches/security/samba-4.8.10-security-2019-04-08.patch
Assigning to the registered maintainer.
Assignee: bugsquad => bgmilneCC: (none) => marja11
Debian has issued an advisory for this on April 8: https://www.debian.org/security/2019/dsa-4427
Ubuntu has issued an advisory for this on April 8: https://usn.ubuntu.com/3939-1/
openSUSE has issued an advisory for this on April 10: https://lists.opensuse.org/opensuse-updates/2019-04/msg00095.html
New release, 4.10.3, fixes CVE-2018-16860 https://www.samba.org/samba/history/samba-4.10.3.html
Status comment: (none) => Fixed upstream in 4.10.3CVE: (none) => CVE-2019-3880 CVE-2018-16860CC: (none) => smelror
https://www.samba.org/samba/security/CVE-2018-16860.html building with MIT krb5 would also fix it.
Summary: samba new security issue CVE-2019-3880 => samba new security issues CVE-2019-3880 and CVE-2018-16860Whiteboard: (none) => MGA6TOOVersion: 6 => Cauldron
samba-4.10.3-1.mga7 uploaded for Cauldron.
Whiteboard: MGA6TOO => (none)Status comment: Fixed upstream in 4.10.3 => (none)Version: Cauldron => 6
Debian advisory for CVE-2018-16860 from May 14: https://www.debian.org/security/2019/dsa-4443
and from Ubuntu: https://usn.ubuntu.com/3976-1/
Mageia 6 is EOL.
Status: NEW => RESOLVEDResolution: (none) => OLD