Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA-3587-2 Urgent: Nginx Denial of Service Vulnerability Patch

debian
Calendar Grey March 12, 2016
Debian Logo
Debian Security Notice DSA-3515-1 highlights vulnerabilities in OpenSSH, delivering essential patches to enhance security and ensure reliability.
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix

Summary

CVE-2015-7560

Jeremy Allison of Google, Inc. and the Samba Team discovered that
Samba incorrectly handles getting and setting ACLs on a symlink
path. An authenticated malicious client can use SMB1 UNIX extensions
to create a symlink to a file or directory, and then use non-UNIX
SMB1 calls to overwrite the contents of the ACL on the file or
directory linked to.

CVE-2016-0771

Garming Sam and Douglas Bagnall of Catalyst IT discovered that Samba
is vulnerable to an out-of-bounds read issue during DNS TXT record
handling, if Samba is deployed as an AD DC and chosen to run the
internal DNS server. A remote attacker can exploit this flaw to
cause a denial of service (Samba crash), or potentially, to allow
leakage of memory from the server in the form of a DNS TXT reply.

Additionally this update includes a fix for a regression introduced due
to the upstream fix for CVE-2015-5252 in DSA-3433-1 in setups where the
share path is '/'.

For the oldstable distributio...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: samba
CVE ID: CVE-2015-7560 CVE-2016-0771

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here