From ${URL} : It was reported [1] that there are no ACL checks done on accessing stream files (as opposed to regular files) when performing generic file operations like read and write. A stream file created on a CIFS share, with explicit deny write ACE applied, would be ignored, despite the access control. This could allow users able to access the CIFS share on which such a restricted stream file existed, to read and write to the stream file when the expectation was that they were not authorized to do so. A patch has been posted to the samba-technical mailing list [2] to correct this flaw. Samba 3.6 and higher are affected by this flaw. [1] https://bugzilla.samba.org/show_bug.cgi?id=10235 [2] https://lists.samba.org/archive/samba-technical/attachments/20131028/3f1fc04c/attachment.patch @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
@maintainers: ping.
Seems that was handled in bug 491070 *** This bug has been marked as a duplicate of bug 491070 ***