2

So, the Badlock bug (www.badlock.org) that was revealed yesterday, was not as terrible as feared. And yet, it seems prudent to patch samba ASAP.

However, just prior to releasing the bug, the samba developers decided to EOL the 4.1.x-branch and did not release a fix for the bug.

At the same time, the version that is available when using 'aptitude update' on a fairly recently installed Ubuntu 14 LTS, is version 4.1.6-Ubuntu.

Has this version been specifically patched for Badlock? If not, what is the best course of action to get samba upgraded to a non-EOL version on Ubuntu?

In the security updates thread, https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages , I see an update coming for samba version 4.3.x. But the version I have is the one that was selected by default when I did the installation, 4.1.6-Ubuntu. I ask this question because I am unsure if that fix is going to apply -- and if so, when.

Niels2000
  • 121

1 Answers1

0

Since you are on 14.04, your packages (in main) get security upgrades for 5 years. I guess the Ubuntu team is already working on that. You'll only need the ppa if you have reason to believe it's going to be exploited at your site before the fix hits official Ubuntu packages.

Jakob Lenfers
  • 1,105
  • 7
  • 17