Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
USN-2950-1 introduced regressions in Samba.
Software Description:
- samba: SMB/CIFS file, print, and login server for Unix
Details:
USN-2950-1 fixed vulnerabilities in Samba. The fixes introduced in Samba
4.3.8 caused certain regressions and interoperability issues.
This update resolves some of these issues by updating to Samba 4.3.9 in
Ubuntu 14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. Backported regression
fixes were added to Samba 3.6.25 in Ubuntu 12.04 LTS.
Original advisory details:
Jouni Knuutinen discovered that Samba contained multiple flaws in the
DCE/RPC implementation. A remote attacker could use this issue to perform
a denial of service, downgrade secure connections by performing a man in
the middle attack, or possibly execute arbitrary code. (CVE-2015-5370)
Stefan Metzmacher discovered that Samba contained multiple flaws in the
NTLMSSP authentication implementation. A remote attacker could use this
issue to downgrade connections t...
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: samba 2:4.3.9+dfsg-0ubuntu0.16.04.1 Ubuntu 15.10: samba 2:4.3.9+dfsg-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: samba 2:4.3.9+dfsg-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: samba 2:3.6.25-0ubuntu0.12.04.3 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2950-2
https://ubuntu.com/security/notices/USN-2950-1
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1577739
Get the latest Linux and open source security news straight to your inbox.