Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE Linux Enterprise 12: 2015:0353-1 Important Samba Security Threat

suse
Calendar Grey February 23, 2015
Scroller Suse
SUSE Security Patch for openssl tackles CVE-2016-2106, delivering crucial enhancements to bolster overall system protection.
An update that solves one vulnerability and has 7 fixes is An update that solves one vulnerability and has 7 fixes is An update that solves one vulnerability and has 7 fixes is now...

Summary

samba was updated to fix one security issue. This security issue was fixed: - CVE-2015-0240: Don't call talloc_free on an uninitialized pointer (bnc#917376). These non-security issues were fixed: - Fix vfs_snapper DBus string handling (bso#11055, bnc#913238). - Fix libsmbclient DFS referral handling. + Reuse connections derived from DFS referrals (bso#10123). + Set domain/workgroup based on authentication callback value (bso#11059). - pam_winbind: Fix warn_pwd_expire implementation (bso#9056). - nsswitch: Fix soname of linux nss_*.so.2 modules (bso#9299). - Fix profiles tool (bso#9629). - s3-lib: Do not require a password with --use-ccache (bso#10279). - s4:dsdb/rootdse: Expand extended dn values with the AS_SYSTEM control (bso#10949). - s4-rpc: dnsserver: Fix enumeration of IPv4 and IPv6 addresses

References

#872912 #873922 #876312 #889175 #898031 #908627

#913238 #917376

Cross- CVE-2015-0240

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-0240.html

https://bugzilla.suse.com/show_bug.cgi?id=872912

https://bugzilla.suse.com/show_bug.cgi?id=873922

https://bugzilla.suse.com/show_bug.cgi?id=876312

https://bugzilla.suse.com/show_bug.cgi?id=889175

https://bugzilla.suse.com/show_bug.cgi?id=898031

https://bugzilla.suse.com/show_bug.cgi?id=908627

https://bugzilla.suse.com/show_bug.cgi?id=913238

https://bugzilla.suse.com/show_bug.cgi?id=917376

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0353-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.