Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 16.04 & 14.04 LTS: USN-3092-1 Moderate: Samba Impersonation

ubuntu
Calendar Grey September 28, 2016
Scroller Ubuntu
Critical flaw in Samba for Ubuntu systems permits distant attackers to mimic servers, posing a security threat. Patch immediately!
Samba could be tricked into connecting to impersonated servers.

Summary

Samba could be tricked into connecting to impersonated servers.

Software Description:

- samba: SMB/CIFS file, print, and login server for Unix

Details:

Stefan Metzmacher discovered that Samba incorrectly handled certain flags

in SMB2/3 client connections. A remote attacker could use this issue to

disable client signing and impersonate servers by performing a man in the

middle attack.

Samba has been updated to 4.3.11 in Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.

In addition to the security fix, the updated packages contain bug fixes,

new features, and possibly incompatible changes.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  samba                           2:4.3.11+dfsg-0ubuntu0.16.04.1

Ubuntu 14.04 LTS:
  samba                           2:4.3.11+dfsg-0ubuntu0.14.04.1

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References

https://ubuntu.com/security/notices/USN-3092-1

CVE-2016-2119

September 28, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.