Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Slackware 14.1: SSA:2016-106-02 Critical: Samba DoS Fix

slackware
Calendar Grey April 15, 2016
Dist Slackware Esm H88
Samba distributions for Slackware deliver critical patches to address vulnerabilities such as Denial of Service and eavesdropping threats.
New samba packages are available for Slackware 14.0, 14.1, and -current to fix security issues

Summary

Here are the details from the Slackware 14.1 ChangeLog: patches/packages/samba-4.2.11-i486-1_slack14.1.txz: Upgraded. This update fixes the security issues known as "badlock" (or "sadlock"), which may allow man-in-the-middle or denial-of-service attacks: CVE-2015-5370 (Multiple errors in DCE-RPC code) CVE-2016-2110 (Man in the middle attacks possible with NTLMSSP) CVE-2016-2111 (NETLOGON Spoofing Vulnerability) CVE-2016-2112 (LDAP client and server don't enforce integrity) CVE-2016-2113 (Missing TLS certificate validation) CVE-2016-2114 ("server signing = mandatory" not enforced) CVE-2016-2115 (SMB IPC traffic is not integrity protected) CVE-2016-2118 (SAMR and LSA man in the middle attacks possible) For more information, see: https://www.cve.org/CVERecord?id=CVE-2015-5370 https://www.cve.org/CVERecord?id=CVE-2016-2110 https://www.cve.org/CVERecord?id=CVE-2016-2111 https://www.cve.org/CVERecord?id=CVE-2016-2112

Read the Full Advisory

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.0 package: 2380bc0ddc5f60c28312bcd7b56ab2be samba-4.2.11-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: d6189a5d2293af40767bc3805d649144 samba-4.2.11-x86_64-1_slack14.0.txz
Slackware 14.1 package: 7d31cf705ccf10346fb0718bc4d9ee3d samba-4.2.11-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: a3db506941de422e75f18a854d82c95f samba-4.2.11-x86_64-1_slack14.1.txz
Slackware -current package: ef51645624e6707f01060ba491ec3dfd n/samba-4.4.2-i586-1.txz
Slackware x86_64 -current package: 2ad90a74923e18b3c3616ef66fc6237a n/samba-4.4.2-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg samba-4.2.11-i486-1_slack14.0.txz Then, if Samba is running restart it: # /etc/rc.d/rc.samba restart

Related News

Your message here