SUSE Security Update: Security update for samba
______________________________________________________________________________

Announcement ID:    SUSE-SU-2016:0905-1
Rating:             important
References:         #936909 #953382 #967017 #968222 
Cross-References:   CVE-2015-7560
Affected Products:
                    SUSE Linux Enterprise Server 11-SP2-LTSS
                    SUSE Linux Enterprise Debuginfo 11-SP2
______________________________________________________________________________

   An update that solves one vulnerability and has three fixes
   is now available.

Description:


   This update for samba fixes the following issues:

   Security issue fixed:
   - CVE-2015-7560: Getting and setting Windows ACLs on symlinks can change
     permissions on link target; (bso#11648); (bsc#968222).

   Bugs fixed:
   - Fix leaking memory in libsmbclient: Add missing talloc stackframe;
     (bso#11177); (bsc#967017).
   - Ensure samlogon fallback requests are rerouted after kerberos failure;
     (bsc#953382).
   - Ensure attempt to ssh into locked account  triggers "Your account is
     disabled....." to the console; (bsc#953382).
   - Make the winbind package depend on the matching libwbclient version and
     vice versa; (bsc#936909).


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server 11-SP2-LTSS:

      zypper in -t patch slessp2-samba-12477=1

   - SUSE Linux Enterprise Debuginfo 11-SP2:

      zypper in -t patch dbgsp2-samba-12477=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server 11-SP2-LTSS (i586 s390x x86_64):

      ldapsmb-1.34b-48.2
      libldb1-3.6.3-48.2
      libsmbclient0-3.6.3-48.2
      libtalloc2-3.6.3-48.2
      libtdb1-3.6.3-48.2
      libtevent0-3.6.3-48.2
      libwbclient0-3.6.3-48.2
      samba-3.6.3-48.2
      samba-client-3.6.3-48.2
      samba-krb-printing-3.6.3-48.2
      samba-winbind-3.6.3-48.2

   - SUSE Linux Enterprise Server 11-SP2-LTSS (s390x x86_64):

      libsmbclient0-32bit-3.6.3-48.2
      libtalloc2-32bit-3.6.3-48.2
      libtdb1-32bit-3.6.3-48.2
      libtevent0-32bit-3.6.3-48.2
      libwbclient0-32bit-3.6.3-48.2
      samba-32bit-3.6.3-48.2
      samba-client-32bit-3.6.3-48.2
      samba-winbind-32bit-3.6.3-48.2

   - SUSE Linux Enterprise Server 11-SP2-LTSS (noarch):

      samba-doc-3.6.3-48.2

   - SUSE Linux Enterprise Debuginfo 11-SP2 (i586 s390x x86_64):

      samba-debuginfo-3.6.3-48.2
      samba-debugsource-3.6.3-48.2

   - SUSE Linux Enterprise Debuginfo 11-SP2 (s390x x86_64):

      samba-debuginfo-32bit-3.6.3-48.2


References:

   https://www.suse.com/security/cve/CVE-2015-7560.html
   https://bugzilla.suse.com/936909
   https://bugzilla.suse.com/953382
   https://bugzilla.suse.com/967017
   https://bugzilla.suse.com/968222

SuSE: 2016:0905-1: important: samba

March 29, 2016
An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes ...

Summary

This update for samba fixes the following issues: Security issue fixed: - CVE-2015-7560: Getting and setting Windows ACLs on symlinks can change permissions on link target; (bso#11648); (bsc#968222). Bugs fixed: - Fix leaking memory in libsmbclient: Add missing talloc stackframe; (bso#11177); (bsc#967017). - Ensure samlogon fallback requests are rerouted after kerberos failure; (bsc#953382). - Ensure attempt to ssh into locked account triggers "Your account is disabled....." to the console; (bsc#953382). - Make the winbind package depend on the matching libwbclient version and vice versa; (bsc#936909). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP2-LTSS: zypper in -t patch slessp2-samba-12477=1 - SUSE Linux Enterprise Debuginfo 11-SP2: zypper in -t patch dbgsp2-samba-12477=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP2-LTSS (i586 s390x x86_64): ldapsmb-1.34b-48.2 libldb1-3.6.3-48.2 libsmbclient0-3.6.3-48.2 libtalloc2-3.6.3-48.2 libtdb1-3.6.3-48.2 libtevent0-3.6.3-48.2 libwbclient0-3.6.3-48.2 samba-3.6.3-48.2 samba-client-3.6.3-48.2 samba-krb-printing-3.6.3-48.2 samba-winbind-3.6.3-48.2 - SUSE Linux Enterprise Server 11-SP2-LTSS (s390x x86_64): libsmbclient0-32bit-3.6.3-48.2 libtalloc2-32bit-3.6.3-48.2 libtdb1-32bit-3.6.3-48.2 libtevent0-32bit-3.6.3-48.2 libwbclient0-32bit-3.6.3-48.2 samba-32bit-3.6.3-48.2 samba-client-32bit-3.6.3-48.2 samba-winbind-32bit-3.6.3-48.2 - SUSE Linux Enterprise Server 11-SP2-LTSS (noarch): samba-doc-3.6.3-48.2 - SUSE Linux Enterprise Debuginfo 11-SP2 (i586 s390x x86_64): samba-debuginfo-3.6.3-48.2 samba-debugsource-3.6.3-48.2 - SUSE Linux Enterprise Debuginfo 11-SP2 (s390x x86_64): samba-debuginfo-32bit-3.6.3-48.2

References

#936909 #953382 #967017 #968222

Cross- CVE-2015-7560

Affected Products:

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2015-7560.html

https://bugzilla.suse.com/936909

https://bugzilla.suse.com/953382

https://bugzilla.suse.com/967017

https://bugzilla.suse.com/968222

Severity
Announcement ID: SUSE-SU-2016:0905-1
Rating: important

Related News