Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2016:0164-1 Important: Samba Remote Exploit Threats Resolved

suse
Calendar Grey January 19, 2016
Scroller Suse
The newest Samba patch resolves several security flaws, providing updates for various SUSE operating systems.
An update that solves four vulnerabilities and has 7 fixes An update that solves four vulnerabilities and has 7 fixes An update that solves four vulnerabilities and has 7 fixes is ...

Summary

This update for Samba fixes the following security issues: - CVE-2015-5330: Remote read memory exploit in LDB (bnc#958586) - CVE-2015-5252: Insufficient symlink verification (file access outside the share) (bnc#958582) - CVE-2015-5296: No man in the middle protection when forcing smb encryption on the client side (bnc#958584) - CVE-2015-5299: Currently the snapshot browsing is not secure thru windows previous version (shadow_copy2) (bnc#958583) Non-security issues fixed: - Prevent null pointer access in samlogon fallback when security credentials are null (bnc#949022) - Ensure samlogon fall-back requests are rerouted after kerberos failure (bnc#953382) - Ensure "Your account is disabled" message is displayed when attempting to ssh into locked account (bnc#953382)

References

#295284 #912457 #934299 #936909 #948244 #949022

#953382 #958582 #958583 #958584 #958586

Cross- CVE-2015-5252 CVE-2015-5296 CVE-2015-5299

CVE-2015-5330

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Software Development Kit 11-SP3

SUSE Linux Enterprise Server for VMWare 11-SP3

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3

SUSE Linux Enterprise Desktop 11-SP4

SUSE Linux Enterprise Desktop 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2015-5252.html

https://www.suse.com/security/cve/CVE-2015-5296.html

https://www.suse.com/security/cve/CVE-2015-5299.html

https://www.suse.com/security/cve/CVE-2015-5330.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0164-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.