Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE Leap 42.1: 2017:1415-1 Critical: Samba Code Execution Risk

opensuse
Calendar Grey May 26, 2017
Dist Opensuse Esm H88
Important Samba patch for openSUSE mitigates vulnerabilities tied to unanticipated code execution. Upgrade is advised.
An update that fixes one vulnerability is now available

Description

This update for samba fixes the following issue:

- An unprivileged user with access to the samba server could cause smbd to

load a specially crafted shared library, which then had the ability to

execute arbitrary code on the server as 'root'. [CVE-2017-7494,

bso#12780, bsc#1038231]

This update was imported from SUSE:SLE-12-SP1:Update project.

NOTE: This update is released in openSUSE Leap 42.1 after its official End

Of Life only because

of its severity and potential impact for users that have not migrated yet.

Please upgrade your openSUSE Leap 42.1 as soon as possible.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2017-618=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

ctdb-4.2.4-33.1

ctdb-debuginfo-4.2.4-33.1

ctdb-devel-4.2.4-33.1

ctdb-tests-4.2.4-33.1

ctdb-tests-debuginfo-4.2.4-33.1

libdcerpc-atsvc-devel-4.2.4-33.1

libdcerpc-atsvc0-4.2.4-33.1

libdcerpc-atsvc0-debuginfo-4.2.4-33.1

libdcerpc-binding0-4.2.4-33.1

libdcerpc-binding0-debuginfo-4.2.4-33.1

libdcerpc-devel-4.2.4-33.1

libdcerpc-samr-devel-4.2.4-33.1

libdcerpc-samr0-4.2.4-33.1

libdcerpc-samr0-debuginfo-4.2.4-33.1

libdcerpc0-4.2.4-33.1

libdcerpc0-debuginfo-4.2.4-33.1

libgensec-devel-4.2.4-33.1

libgensec0-4.2.4-33.1

libgensec0-debuginfo-4.2.4-33.1

libndr-devel-4.2.4-33.1

libndr-krb5pac-devel-4.2.4-33.1

libndr-krb5pac0-4.2.4-33.1

libndr-krb5pac0-debuginfo-4.2.4-33.1

libndr-nbt-devel-4.2.4-33.1

libndr-nbt0-4.2.4-33.1

libndr-nbt0-debuginfo-4.2.4-33.1

libndr-standard-devel-4.2.4-33.1

libndr-standard0-4.2.4-33.1

libndr-standard0-debuginfo-4.2.4-33.1

libndr0-4.2.4-33.1

libndr0-debuginfo-4.2.4-33.1

libnetapi-devel-4.2.4-33.1

libnetapi0-4.2.4-33.1

libnetapi0-debuginfo-4.2.4-33.1

libregistry-devel-4.2....

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-7494.html

https://bugzilla.suse.com/1038231

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:1415-1
Rating: important
Affected Products: openSUSE Leap 42.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here