Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing this update, the smb service will be restarted
automatically.
Samba is an open-source implementation of the Server Message Block (SMB)
protocol and the related Common Internet File System (CIFS) protocol, which
allow PC-compatible machines to share files, printers, and various
information.
Security Fix(es):
* A use-after-free flaw was found in the way samba servers handled certain
SMB1 requests. An unauthenticated attacker could send specially-crafted
SMB1 requests to cause the server to crash or execute arbitrary code.
(CVE-2017-14746)
* A memory disclosure flaw was found in samba. An attacker could retrieve
parts of server memory, which could contain potentially sensitive data, by
sending specially-crafted requests to the samba server. (CVE-2017-15275)
Red Hat would like to thank the Samba project for reporting these issues.
Upstream acknowledges Yihan Lian and Zhibin Hu (Qihoo 360 GearTeam) as the
original reporter of CVE-2017-14746; and Volker Lendecke (SerNet and the
Samba Team) as the original reporter of CVE-2017-15275.
https://access.redhat.com/security/cve/CVE-2017-14746 https://access.redhat.com/security/cve/CVE-2017-15275 https://access.redhat.com/security/updates/classification#important
Red Hat Enterprise Linux Client (v. 7):
Source:
samba-4.6.2-12.el7_4.src.rpm
noarch:
samba-common-4.6.2-12.el7_4.noarch.rpm
x86_64:
libsmbclient-4.6.2-12.el7_4.i686.rpm
libsmbclient-4.6.2-12.el7_4.x86_64.rpm
libwbclient-4.6.2-12.el7_4.i686.rpm
libwbclient-4.6.2-12.el7_4.x86_64.rpm
samba-client-4.6.2-12.el7_4.x86_64.rpm
samba-client-libs-4.6.2-12.el7_4.i686.rpm
samba-client-libs-4.6.2-12.el7_4.x86_64.rpm
samba-common-libs-4.6.2-12.el7_4.x86_64.rpm
samba-common-tools-4.6.2-12.el7_4.x86_64.rpm
samba-debuginfo-4.6.2-12.el7_4.i686.rpm
samba-debuginfo-4.6.2-12.el7_4.x86_64.rpm
samba-krb5-printing-4.6.2-12.el7_4.x86_64.rpm
samba-libs-4.6.2-12.el7_4.i686.rpm
samba-libs-4.6.2-12.el7_4.x86_64.rpm
samba-winbind-4.6.2-12.el7_4.x86_64.rpm
samba-winbind-clients-4.6.2-12.el7_4.x86_64.rpm
samba-winbind-modules-4.6.2-12.el7_4.i686.rpm
samba-winbind-modules-4.6.2-12.el7_4.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
noarch:
samba-pidl-4.6.2-12.el7_4.noarch.rpm
x86_64:
libsmbclient-devel-4.6.2-12.el7_4.i686.rpm
libsmbclient-devel-4.6.2-12.el7_4.x86_64.rpm
libwbclient-devel-4.6.2-12.el7_4.i686.rpm
libwbclient-devel-4.6.2-12.el7_4.x86_64.rpm
samba-4.6.2-12.el7_4.x86_64.rpm
samba-dc-4.6.2-12.el7_4.x86_64.rpm
samba-dc-libs-4.6.2-12.el7_4.x86_64.rpm
Read the Full Advisory
An update for samba is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Resilient Storage (v. 7) - ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, noarch, ppc64le
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, noarch, ppc64le
1511899 - CVE-2017-14746 samba: Use-after-free in processing SMB1 requests
1512465 - CVE-2017-15275 samba: Server heap-memory disclosure
Get the latest Linux and open source security news straight to your inbox.