Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Debian 8: DLA-1539-1 Critical Samba Data Exposure and Validation

debian lts
Calendar Grey October 8, 2018
Scroller Debian Lts
Important security patch for Samba resolving various vulnerabilities on Debian 8. Please update to version 4.2.14+dfsg-0+deb8u10 immediately.
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix

Summary

Svyatoslav Phirsov discovered that insufficient input validation in
libsmbclient allowed a malicious Samba server to write to the
client's heap memory.

CVE-2018-10919

Phillip Kuhrt discovered that Samba when acting as an Active Domain
controller disclosed some sensitive attributes.

For Debian 8 "Jessie", these problems have been fixed in version
4.2.14+dfsg-0+deb8u10.

We recommend that you upgrade your samba packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: samba
Version: 4.2.14+dfsg-0+deb8u10
CVE ID: CVE-2018-10858 CVE-2018-10919

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.