NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
PHolder
May 25, 2017Aspirant
Any plans for Samba fix for CVE-2017-7494 ?
I posted elsewhere about this, but CVE-2017-7494 NEEDs to be patched on any device still in operation, and I think that includes the older, technically out of support models that I have 6 of. Wit...
- May 30, 2017
Legacy Sparc, x86 and ARM firmware is now available:
RAIDiator-4.1.16 (Sparc)
Danthem
May 25, 2017NETGEAR Employee
Hi PHolder,
A firmware upgrade with this patched is already released, 6.7.3:
https://kb.netgear.com/000038777/ReadyNAS-OS-6-Software-Version-6-7-3
sfriis
May 26, 2017Tutor
I just upgraded to 6.7.3, but appearantly smbd is still v 4.4.9:
Welcome to ReadyNASOS 6.7.3
Last login: Fri May 26 12:58:49 2017 from xxxxx
root@xxxxxx:~# smbd --version
Version 4.4.9
root@xxxxxx:~#
Am I missing something??
- ctechsMay 26, 2017Apprentice
Since this was a point release, the netgear team likely backported the fix instead of upgrading samba to the latest and greatest, to avoid breaking things.
- mdgm-ntgrMay 26, 2017NETGEAR Employee Retired
ctechs wrote:
Since this was a point release, the netgear team likely backported the fix instead of upgrading samba to the latest and greatest, to avoid breaking things.
Exactly. In time we'll move to a newer version of samba on OS6, but for now we backported the fix.
If you look at packages.log (or do a dpkg -l) you'll see that the netgearx at the end of the version of the samba package is incremented by one (where x is a number) compared with the logs you downloaded before updating to 6.7.3. That indicates that we've added some more patches to the samba 4.4.9 code.- mdgm-ntgrMay 27, 2017NETGEAR Employee Retired
We have a KB article: Security Advisory for CVE-2017-7494, Samba Remote Code Execution
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!