Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
USN-2950-1 introduced regressions in Samba.
Software Description:
- samba: SMB/CIFS file, print, and login server for Unix
Details:
USN-2950-1 fixed vulnerabilities in Samba. The backported fixes introduced
in Ubuntu 12.04 LTS caused interoperability issues. This update fixes
compatibility with certain NAS devices, and allows connecting to Samba 3.6
servers by relaxing the "client ipc signing" parameter to "auto".
We apologize for the inconvenience.
Original advisory details:
Jouni Knuutinen discovered that Samba contained multiple flaws in the
DCE/RPC implementation. A remote attacker could use this issue to perform
a denial of service, downgrade secure connections by performing a man in
the middle attack, or possibly execute arbitrary code. (CVE-2015-5370)
Stefan Metzmacher discovered that Samba contained multiple flaws in the
NTLMSSP authentication implementation. A remote attacker could use this
issue to downgrade connections to plain text b...
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: samba 2:3.6.25-0ubuntu0.12.04.4 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2950-4
https://ubuntu.com/security/notices/USN-2950-1
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1574403, https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1576109
Get the latest Linux and open source security news straight to your inbox.