Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for Samba fixes the following security issues: - CVE-2015-5330: Remote read memory exploit in LDB (bnc#958586). - CVE-2015-5252: Insufficient symlink verification (file access outside the share) (bnc#958582). - CVE-2015-5296: No man in the middle protection when forcing smb encryption on the client side (bnc#958584). - CVE-2015-5299: Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2) (bnc#958583). Non-security issues fixed: - Prevent null pointer access in samlogon fallback when security credentials are null (bnc#949022). - Address unrecoverable winbind failure: "key length too large" (bnc#934299). - Take resource group sids into account when caching netsamlogon data (bnc#912457).
#295284 #773464 #901813 #912457 #913304 #934299
#948244 #949022 #958582 #958583 #958584 #958586
Cross- CVE-2015-5252 CVE-2015-5296 CVE-2015-5299
CVE-2015-5330
Affected Products:
SUSE Linux Enterprise Server 11-SP2-LTSS
SUSE Linux Enterprise Debuginfo 11-SP2
https://www.suse.com/security/cve/CVE-2015-5252.html
https://www.suse.com/security/cve/CVE-2015-5296.html
https://www.suse.com/security/cve/CVE-2015-5299.html
https://www.suse.com/security/cve/CVE-2015-5330.html
https://bugzilla.suse.com/show_bug.cgi?id=295284
https://bugzilla.suse.com/show_bug.cgi?id=773464
https://bugzilla.suse.com/show_bug.cgi?id=901813
https://bugzilla.suse.com/show_bug.cgi?id=912457
https://bugzilla.suse.com/show_bug.cgi?id=913304
Get the latest Linux and open source security news straight to your inbox.