Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 ESM: USN-3426-2 Critical Samba Remote Access Threat

ubuntu
Calendar Grey November 2, 2017
Scroller Ubuntu
Multiple Samba security flaws have been addressed in Ubuntu 12.04 ESM. Make sure to update your system to safeguard against potential threats.
Several security issues were fixed in XXX-APP-XXX.

Summary

Several security issues were fixed in XXX-APP-XXX.

Software Description:

- samba: SMB/CIFS file, print, and login server for Unix

Details:

USN-3426-1 fixed several vulnerabilities in Samba. This update

provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Stefan Metzmacher discovered that Samba incorrectly enforced SMB

 signing in certain situations. A remote attacker could use this issue

 to perform a man in the middle attack. (CVE-2017-12150)

 Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled

 memory when SMB1 is being used. A remote attacker could possibly use

 this issue to obtain server memory contents. (CVE-2017-12163)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  samba                           2:3.6.25-0ubuntu0.12.04.13

In general, a standard system update will make all the necessary
changes.

References

  https://ubuntu.com/security/notices/USN-3426-2

  https://ubuntu.com/security/notices/USN-3426-1

  CVE-2017-12150, CVE-2017-12163

Severity
critical
Lowest
Low
Medium
High
Critical

November 02, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.