Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 12.04 ESM: USN-3426-2 Critical Samba Remote Access Threat

Ubuntu Large Esm H500
Several security issues were fixed in XXX-APP-XXX.
=========================================================================Ubuntu Security Notice USN-3426-2
November 02, 2017

samba vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in XXX-APP-XXX.

Software Description:
- samba: SMB/CIFS file, print, and login server for Unix

Details:

USN-3426-1 fixed several vulnerabilities in Samba. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Stefan Metzmacher discovered that Samba incorrectly enforced SMB
 signing in certain situations. A remote attacker could use this issue
 to perform a man in the middle attack. (CVE-2017-12150)

 Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled
 memory when SMB1 is being used. A remote attacker could possibly use
 this issue to obtain server memory contents. (CVE-2017-12163)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  samba                           2:3.6.25-0ubuntu0.12.04.13

In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-3426-2
  https://ubuntu.com/security/notices/USN-3426-1
  CVE-2017-12150, CVE-2017-12163

Ubuntu 12.04 ESM: USN-3426-2 Critical Samba Remote Access Threat

ubuntu
Calendar Grey November 2, 2017
Dist Ubuntu Esm H88
Multiple Samba security flaws have been addressed in Ubuntu 12.04 ESM. Make sure to update your system to safeguard against potential threats.
Several security issues were fixed in XXX-APP-XXX.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM:   samba                           2:3.6.25-0ubuntu0.12.04.13 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3426-2

  https://ubuntu.com/security/notices/USN-3426-1

  CVE-2017-12150, CVE-2017-12163

Severity
critical
Lowest
Low
Medium
High
Critical

November 02, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here