Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 14.04 LTS: USN-2922-1 Critical Samba Access Control Issues

ubuntu
Calendar Grey March 8, 2016
Scroller Ubuntu
Multiple Samba vulnerabilities patched in Ubuntu. Ensure your system is up-to-date for ongoing security and reliability.
Several security issues were fixed in Samba.

Summary

Several security issues were fixed in Samba.

Software Description:

- samba: SMB/CIFS file, print, and login server for Unix

Details:

Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink

paths. A remote attacker could use this issue to overwrite the ownership of

ACLs using symlinks. (CVE-2015-7560)

Garming Sam and Douglas Bagnall discovered that the Samba internal DNS

server incorrectly handled certain DNS TXT records. A remote attacker could

use this issue to cause Samba to crash, resulting in a denial of service,

or possibly obtain uninitialized memory contents. This issue only applied

to Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)

It was discovered that the Samba Web Administration Tool (SWAT) was

vulnerable to clickjacking and cross-site request forgery attacks. This

issue only affected Ubuntu 12.04 LTS. (CVE-2013-0213, CVE-2013-0214)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  samba                           2:4.1.17+dfsg-4ubuntu3.3

Ubuntu 14.04 LTS:
  samba                           2:4.1.6+dfsg-1ubuntu2.14.04.13

Ubuntu 12.04 LTS:
  samba                           2:3.6.3-2ubuntu2.17
  swat                            2:3.6.3-2ubuntu2.17

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2922-1

CVE-2013-0213, CVE-2013-0214, CVE-2015-7560, CVE-2016-0771

Severity
critical
Lowest
Low
Medium
High
Critical

March 08, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.