Debian LTS: DLA-1754-1: samba security update

    Date09 Apr 2019
    CategoryDebian LTS
    389
    Posted ByLinuxSecurity Advisories
    Various vulnerabilities were discovered in Samba, SMB/CIFS file, print, and login server/client for Unix
    Package        : samba
    Version        : 2:4.2.14+dfsg-0+deb8u12
    CVE ID         : CVE-2017-9461 CVE-2018-1050 CVE-2018-1057 CVE-2019-3880
    
    
    Various vulnerabilities were discovered in Samba, SMB/CIFS file, print,
    and login server/client for Unix
    
    CVE-2017-9461
    
        smbd in Samba had a denial of service vulnerability (fd_open_atomic
        infinite loop with high CPU usage and memory consumption) due to
        wrongly handling dangling symlinks.
    
    CVE-2018-1050
    
        Samba was vulnerable to a denial of service attack when the RPC
        spoolss service was configured to be run as an external daemon.
        Missing input sanitization checks on some of the input parameters to
        spoolss RPC calls could have caused the print spooler service to
        crash.
    
    CVE-2018-1057
    
        On a Samba 4 AD DC the LDAP server of Samba incorrectly validated
        permissions to modify passwords over LDAP allowing authenticated
        users to change any other users' passwords, including administrative
        users and privileged service accounts (eg Domain Controllers).
    
        Thanks to the Ubuntu security team for having backported the rather
        invasive changeset to Samba in Ubuntu 14.04 (which we could use to
        patch Samba in Debian jessie LTS).
    
    CVE-2019-3880
    
        A flaw was found in the way Samba implemented an RPC endpoint
        emulating the Windows registry service API. An unprivileged attacker
        could have used this flaw to create a new registry hive file anywhere
        they had unix permissions which could have lead to creation of a new
        file in the Samba share.
    
    For Debian 8 "Jessie", these problems have been fixed in version
    2:4.2.14+dfsg-0+deb8u12.
    
    We recommend that you upgrade your samba packages.
    
    Further information about Debian LTS security advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://wiki.debian.org/LTS
    
    -- 
    
    mike gabriel aka sunweaver (Debian Developer)
    fon: +49 (1520) 1976 148
    
    GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
    mail: This email address is being protected from spambots. You need JavaScript enabled to view it., http://sunweavers.net
    
    
    You are not authorised to post comments.

    LinuxSecurity Poll

    Has your email account ever been pwned in a data breach?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 2 answer(s).
    /component/communitypolls/?task=poll.vote
    12
    radio
    [{"id":"53","title":"Yes","votes":"5","type":"x","order":"1","pct":83.33,"resources":[]},{"id":"54","title":"No","votes":"1","type":"x","order":"2","pct":16.67,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.