Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Slackware 15.0 Update: SSA 2022-351-01 Critical Samba Privilege Risk

slackware
Calendar Grey December 17, 2022
Dist Slackware Esm H88
Recent Samba updates for Slackware 15.0 tackle critical security flaws, specifically those which could lead to unauthorized privilege escalation.
New samba packages are available for Slackware 15.0 and -current to fix security issues

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/samba-4.15.13-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: This is the Samba CVE for the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability disclosed by Microsoft on Nov 8 2022. A Samba Active Directory DC will issue weak rc4-hmac session keys for use between modern clients and servers despite all modern Kerberos implementations supporting the aes256-cts-hmac-sha1-96 cipher. On Samba Active Directory DCs and members 'kerberos encryption types = legacy' would force rc4-hmac as a client even if the server supports aes128-cts-hmac-sha1-96 and/or aes256-cts-hmac-sha1-96. This is the Samba CVE for the Windows Kerberos Elevation of Privilege Vulnerability disclosed by Microsoft on Nov 8 2022. A service account with the special constrained delegation permission could forge a more powerful ticket than the one it was presented with. The "RC4" protection of

Read the Full Advisory

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 15.0:
Updated package for Slackware x86_64 15.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 15.0 package: 4f00b47c418d2cc088c583214fcae013 samba-4.15.13-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: 17a8269e24b94c18079ab854d99c4558 samba-4.15.13-x86_64-1_slack15.0.txz
Slackware -current package: 742f1ba1ddcb483294d8c8b172aaa8b4 n/samba-4.17.4-i586-1.txz
Slackware x86_64 -current package: dfb34c60cfe6a4dea5d3ab03ddc109f7 n/samba-4.17.4-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg samba-4.15.13-i586-1_slack15.0.txz Then, if Samba is running restart it: # /etc/rc.d/rc.samba restart

Related News

Your message here