HP CIFS Server 3.0f Release Notes version A.02.03

New Fixes in HP CIFS Server A.02.03
HP CIFS Server A.02.03 provides the following defect fixes:
Security Defect Security Bulletin: HPSBUX02155 SSRT061235 rev.2
JAGag15603
A potential security vulnerability has been identified with HP-UX running CIFS Server (Samba). This
vulnerability may permit unauthorized access or local authenticated user to gain elevated privileges.
Memory Depletion
JAGag12260
The smbd daemon maintains internal data structures used track active connections to file and printer
shares. In certain circumstances an attacker may be able to continually increase the memory usage
of an smbd process by issuing a large number of share connection requests. The risk is low.
CIFS-LIB is not automatically marked when selecting CIFS-RUN
(JAGaf96010)
This fix resolves a problem where if the CIFS-RUN fileset is marked for installation, the CIFS-LIB
fileset is not automatically selected. The CIFS-RUN and CIFS-LIB filesets depend on each other.
Therefore, if one fileset is marked for installation, the other fileset must be automatically marked.
Documentation updates with warnings when sharing tdb files with NFS
(JAGaf83991)
Updates both the HP CIFS Server Administrator's Guide and the HA README file with the warning
info that sharing CIFS system files concurrently via NFS can lead to corruption.
The smbd option -l override the desired "log file" smb.conf parameter location
(JAGag07160)
The smbd option -l can be used to override the default CIFS log file location. However, once the
smb.conf parameter "log file" is read by the daemon, it had been expected that the smb.conf log
file specification would be used for during of the logging. This fix changes the precedence, so that if
(and only if) a log file name is specified with the smb.conf parameter "log file" then it will override
the smbd -l option once the smb.conf file is read during the daemon's initialization.
wbinfo -u and -g commands performed poorly with large numbers of users or groups
JAGag14944
Wbinfo has been improved to return results even with very large numbers of users or groups. Also,
when the security model is ADS, wbinfo will return with the results of the query faster than with
previous versions.
Incorrect ownership in large directory search priority
JAGag15603
This fix resolves a problem that may result in incorrect ownership of Windows logon user during
file creation with "large directory search priority" enabled.
Test HP CIFS Server with Red Hat Directory Server
JAGag13489
Red Hat Directory Server v7 has been proven to work compatibly with HP CIFS Server A.02.03 and
will be supported.
New Fixes in HP CIFS Server A.02.03 11