Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu: 2950-1 Moderate: Samba DoS And Spoofing Attacks Mitigation

ubuntu
Calendar Grey April 18, 2016
Scroller Ubuntu
Multiple vulnerabilities in Samba impact Ubuntu versions 12.04, 14.04 LTS, and 15.10. It's vital to review corrective actions and the importance of implementing these updates
Several security issues were fixed in Samba.

Summary

Several security issues were fixed in Samba.

Software Description:

- samba: SMB/CIFS file, print, and login server for Unix

Details:

Jouni Knuutinen discovered that Samba contained multiple flaws in the

DCE/RPC implementation. A remote attacker could use this issue to perform

a denial of service, downgrade secure connections by performing a man in

the middle attack, or possibly execute arbitrary code. (CVE-2015-5370)

Stefan Metzmacher discovered that Samba contained multiple flaws in the

NTLMSSP authentication implementation. A remote attacker could use this

issue to downgrade connections to plain text by performing a man in the

middle attack. (CVE-2016-2110)

Alberto Solino discovered that a Samba domain controller would establish a

secure connection to a server with a spoofed computer name. A remote

attacker could use this issue to obtain sensitive information.

(CVE-2016-2111)

Stefan Metzmacher discovered that the Samba LDAP implementation did not

enf...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  samba                           2:4.3.8+dfsg-0ubuntu0.15.10.2

Ubuntu 14.04 LTS:
  samba                           2:4.3.8+dfsg-0ubuntu0.14.04.2

Ubuntu 12.04 LTS:
  samba                           2:3.6.25-0ubuntu0.12.04.2

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References

https://ubuntu.com/security/notices/USN-2950-1

CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,

CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118

April 18, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.