Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2016:1025-2 Critical: OpenSSL Vulnerability Mitigation Notice

suse
Calendar Grey April 13, 2016
Dist Suse Esm H88
SUSE Security Advisory for Samba: Urgent patches released to mitigate risks, applicable to multiple SUSE platforms.
An update that solves 7 vulnerabilities and has 5 fixes is An update that solves 7 vulnerabilities and has 5 fixes is An update that solves 7 vulnerabilities and has 5 fixes is now...

Summary

samba was updated to fix seven security issues. These security issues were fixed: - CVE-2015-5370: DCERPC server and client were vulnerable to DOS and MITM attacks (bsc#936862). - CVE-2016-2110: A man-in-the-middle could have downgraded NTLMSSP authentication (bsc#973031). - CVE-2016-2111: Domain controller netlogon member computer could have been spoofed (bsc#973032). - CVE-2016-2112: LDAP conenctions were vulnerable to downgrade and MITM attack (bsc#973033). - CVE-2016-2113: TLS certificate validation were missing (bsc#973034). - CVE-2016-2115: Named pipe IPC were vulnerable to MITM attacks (bsc#973036). - CVE-2016-2118: "Badlock" DCERPC impersonation of authenticated account were possible (bsc#971965). These non-security issues were fixed:

References

#924519 #936862 #968973 #971965 #972197 #973031

#973032 #973033 #973034 #973036 #973832 #974629

Cross- CVE-2015-5370 CVE-2016-2110 CVE-2016-2111

CVE-2016-2112 CVE-2016-2113 CVE-2016-2115

CVE-2016-2118

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP1

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise High Availability 12-SP1

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2015-5370.html

https://www.suse.com/security/cve/CVE-2016-2110.html

https://www.suse.com/security/cve/CVE-2016-2111.html

https://www.suse.com/security/cve/CVE-2016-2112.html

https://www.suse.com/security/cve/CVE-2016-2113.html

https://www.suse.com/security/cve/CVE-2016-2115.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1024-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here