Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update fixes libsoup NTLM authentication.
Software Description:
- libsoup2.4: HTTP client/server library for GNOME
Details:
USN-2950-1 fixed vulnerabilities in Samba. The updated Samba packages
introduced a compatibility issue with NTLM authentication in libsoup. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Jouni Knuutinen discovered that Samba contained multiple flaws in the
DCE/RPC implementation. A remote attacker could use this issue to perform
a denial of service, downgrade secure connections by performing a man in
the middle attack, or possibly execute arbitrary code. (CVE-2015-5370)
Stefan Metzmacher discovered that Samba contained multiple flaws in the
NTLMSSP authentication implementation. A remote attacker could use this
issue to downgrade connections to plain text by performing a man in the
middle attack. (CVE-2016-2110)
Alberto Solino discovered that a Samba domain controller ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libsoup2.4-1 2.52.2-1ubuntu0.1 Ubuntu 15.10: libsoup2.4-1 2.50.0-2ubuntu0.1 Ubuntu 14.04 LTS: libsoup2.4-1 2.44.2-1ubuntu2.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2950-2
https://ubuntu.com/security/notices/USN-2950-1
https://bugs.launchpad.net/libsoup/+bug/1573494
Get the latest Linux and open source security news straight to your inbox.