Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE 13.1: 2016:1106-1 Important Samba DoS And MITM

opensuse
Calendar Grey April 20, 2016
Dist Opensuse Esm H88
Important security patch for Samba in openSUSE addressing multiple vulnerabilities, along with vital guidelines.
An update that fixes 17 vulnerabilities is now available

Description

This update fixes these security vulnerabilities:

- CVE-2015-5370: DCERPC server and client were vulnerable to DOS and MITM

attacks (bsc#936862).

- CVE-2016-2110: A man-in-the-middle could have downgraded NTLMSSP

authentication (bsc#973031).

- CVE-2016-2111: Domain controller netlogon member computer could have

been spoofed (bsc#973032).

- CVE-2016-2112: LDAP conenctions were vulnerable to downgrade and MITM

attack (bsc#973033).

- CVE-2016-2113: TLS certificate validation were missing (bsc#973034).

- CVE-2016-2114: "server signing = mandatory" not enforced (bsc#973035).

- CVE-2016-2115: Named pipe IPC were vulnerable to MITM attacks

(bsc#973036).

- CVE-2016-2118: "Badlock" DCERPC impersonation of authenticated account

were possible (bsc#971965).

The openSUSE 13.1 update also upgrades to samba 4.2.4 as 4.1.x versions

are no longer supported by upstream. As a side effect, libpdb0 package was

replaced by...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch 2016-490=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i586 x86_64):

ctdb-4.2.4-3.54.2

ctdb-debuginfo-4.2.4-3.54.2

ctdb-devel-4.2.4-3.54.2

ctdb-pcp-pmda-4.2.4-3.54.2

ctdb-pcp-pmda-debuginfo-4.2.4-3.54.2

ctdb-tests-4.2.4-3.54.2

ctdb-tests-debuginfo-4.2.4-3.54.2

libdcerpc-atsvc-devel-4.2.4-3.54.2

libdcerpc-atsvc0-4.2.4-3.54.2

libdcerpc-atsvc0-debuginfo-4.2.4-3.54.2

libdcerpc-binding0-4.2.4-3.54.2

libdcerpc-binding0-debuginfo-4.2.4-3.54.2

libdcerpc-devel-4.2.4-3.54.2

libdcerpc-samr-devel-4.2.4-3.54.2

libdcerpc-samr0-4.2.4-3.54.2

libdcerpc-samr0-debuginfo-4.2.4-3.54.2

libdcerpc0-4.2.4-3.54.2

libdcerpc0-debuginfo-4.2.4-3.54.2

libgensec-devel-4.2.4-3.54.2

libgensec0-4.2.4-3.54.2

libgensec0-debuginfo-4.2.4-3.54.2

libndr-devel-4.2.4-3.54.2

libndr-krb5pac-devel-4.2.4-3.54.2

libndr-krb5pac0-4.2.4-3.54.2

libndr-krb5pac0-debuginfo-4.2.4-3.54.2

libndr-nbt-devel-4.2.4-3.54.2

libndr-nbt0-4.2.4-3.54.2

libndr-nbt0-debuginfo-4.2.4-3.54.2

libndr-standard-devel-4.2.4-3.54.2

libndr-standard0-4.2.4-3.54.2

libndr-standard0-debuginfo-4.2.4-3.54.2

libndr0-4.2.4-3.54.2

libndr0-deb...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2012-6150.html

https://www.suse.com/security/cve/CVE-2013-4408.html

https://www.suse.com/security/cve/CVE-2013-4496.html

https://www.suse.com/security/cve/CVE-2015-0240.html

https://www.suse.com/security/cve/CVE-2015-5252.html

https://www.suse.com/security/cve/CVE-2015-5296.html

https://www.suse.com/security/cve/CVE-2015-5299.html

https://www.suse.com/security/cve/CVE-2015-5330.html

https://www.suse.com/security/cve/CVE-2015-5370.html

https://www.suse.com/security/cve/CVE-2015-7560.html

https://www.suse.com/security/cve/CVE-2016-2110.html

https://www.suse.com/security/cve/CVE-2016-2111.html

https://www.suse.com/security/cve/CVE-2016-2112.html

https://www.suse.com/security/cve/CVE-2016-2113.html

https://www.suse.com/security/cve/CVE-2016-2114.html

https://www.suse.com/security/cve/CVE-2016-2115.html

https://www.suse.com/security/cve/CVE-2016-2118.html

https://bugzilla.suse.com/844720

https://bugzilla.suse.com/849224

https://bugzilla.suse.com/853347

https://bugzilla.sus...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1106-1
Rating: important
Affected Products: openSUSE 13.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here