Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2016:0032-1 Important: Samba Remote Access Security Flaws

suse
Calendar Grey January 5, 2016
Scroller Suse
The latest SUSE update tackles crucial Samba vulnerabilities, implementing a series of fixes aimed at bolstering overall security.
An update that solves four vulnerabilities and has 8 fixes An update that solves four vulnerabilities and has 8 fixes An update that solves four vulnerabilities and has 8 fixes is ...

Summary

This update for Samba fixes the following security issues: - CVE-2015-5330: Remote read memory exploit in LDB (bnc#958586). - CVE-2015-5252: Insufficient symlink verification (file access outside the share) (bnc#958582). - CVE-2015-5296: No man in the middle protection when forcing smb encryption on the client side (bnc#958584). - CVE-2015-5299: Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2) (bnc#958583). Non-security issues fixed: - Prevent null pointer access in samlogon fallback when security credentials are null (bnc#949022). - Address unrecoverable winbind failure: "key length too large" (bnc#934299). - Take resource group sids into account when caching netsamlogon data (bnc#912457).

References

#295284 #773464 #901813 #912457 #913304 #934299

#948244 #949022 #958582 #958583 #958584 #958586

Cross- CVE-2015-5252 CVE-2015-5296 CVE-2015-5299

CVE-2015-5330

Affected Products:

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2015-5252.html

https://www.suse.com/security/cve/CVE-2015-5296.html

https://www.suse.com/security/cve/CVE-2015-5299.html

https://www.suse.com/security/cve/CVE-2015-5330.html

https://bugzilla.suse.com/show_bug.cgi?id=295284

https://bugzilla.suse.com/show_bug.cgi?id=773464

https://bugzilla.suse.com/show_bug.cgi?id=901813

https://bugzilla.suse.com/show_bug.cgi?id=912457

https://bugzilla.suse.com/show_bug.cgi?id=913304

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0032-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.