An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for samba ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1391-1 Rating: important References: #1038231 Cross-References: CVE-2017-7494 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for samba fixes the following issue: - An unprivileged user with access to the samba server could cause smbd to load a specially crafted shared library, which then had the ability to execute arbitrary code on the server as 'root'. [CVE-2017-7494, bso#12780, bsc#1038231] Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-samba-13127=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-samba-13127=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-samba-13127=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-samba-13127=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-samba-13127=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-samba-13127=1 To bring yoursystem up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libldb-devel-3.6.3-93.1 libnetapi-devel-3.6.3-93.1 libnetapi0-3.6.3-93.1 libsmbclient-devel-3.6.3-93.1 libsmbsharemodes-devel-3.6.3-93.1 libsmbsharemodes0-3.6.3-93.1 libtalloc-devel-3.6.3-93.1 libtdb-devel-3.6.3-93.1 libtevent-devel-3.6.3-93.1 libwbclient-devel-3.6.3-93.1 samba-devel-3.6.3-93.1 samba-test-3.6.3-93.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): ldapsmb-1.34b-93.1 libldb1-3.6.3-93.1 libsmbclient0-3.6.3-93.1 libtalloc2-3.6.3-93.1 libtdb1-3.6.3-93.1 libtevent0-3.6.3-93.1 libwbclient0-3.6.3-93.1 samba-3.6.3-93.1 samba-client-3.6.3-93.1 samba-krb-printing-3.6.3-93.1 samba-winbind-3.6.3-93.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libsmbclient0-32bit-3.6.3-93.1 libtalloc2-32bit-3.6.3-93.1 libtdb1-32bit-3.6.3-93.1 libtevent0-32bit-3.6.3-93.1 libwbclient0-32bit-3.6.3-93.1 samba-32bit-3.6.3-93.1 samba-client-32bit-3.6.3-93.1 samba-winbind-32bit-3.6.3-93.1 - SUSE Linux Enterprise Server 11-SP4 (noarch): samba-doc-3.6.3-93.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libsmbclient0-x86-3.6.3-93.1 libtalloc2-x86-3.6.3-93.1 libtdb1-x86-3.6.3-93.1 libtevent0-x86-3.6.3-93.1 libwbclient0-x86-3.6.3-93.1 samba-client-x86-3.6.3-93.1 samba-winbind-x86-3.6.3-93.1 samba-x86-3.6.3-93.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): ldapsmb-1.34b-93.1 libldb1-3.6.3-93.1 libsmbclient0-3.6.3-93.1 libtalloc2-3.6.3-93.1 libtdb1-3.6.3-93.1 libtevent0-3.6.3-93.1 libwbclient0-3.6.3-93.1 samba-3.6.3-93.1 samba-client-3.6.3-93.1 samba-krb-printing-3.6.3-93.1 samba-winbind-3.6.3-93.1 - SUSELinux Enterprise Server 11-SP3-LTSS (s390x x86_64): libsmbclient0-32bit-3.6.3-93.1 libtalloc2-32bit-3.6.3-93.1 libtdb1-32bit-3.6.3-93.1 libtevent0-32bit-3.6.3-93.1 libwbclient0-32bit-3.6.3-93.1 samba-32bit-3.6.3-93.1 samba-client-32bit-3.6.3-93.1 samba-winbind-32bit-3.6.3-93.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (noarch): samba-doc-3.6.3-93.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (noarch): samba-doc-3.6.3-93.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): ldapsmb-1.34b-93.1 libldb1-3.6.3-93.1 libsmbclient0-3.6.3-93.1 libtalloc2-3.6.3-93.1 libtdb1-3.6.3-93.1 libtevent0-3.6.3-93.1 libwbclient0-3.6.3-93.1 samba-3.6.3-93.1 samba-client-3.6.3-93.1 samba-krb-printing-3.6.3-93.1 samba-winbind-3.6.3-93.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): samba-debuginfo-3.6.3-93.1 samba-debugsource-3.6.3-93.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (ppc64 s390x x86_64): samba-debuginfo-32bit-3.6.3-93.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (ia64): samba-debuginfo-x86-3.6.3-93.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): samba-debuginfo-3.6.3-93.1 samba-debugsource-3.6.3-93.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (s390x): samba-debuginfo-32bit-3.6.3-93.1 References: https://www.suse.com/security/cve/CVE-2017-7494.html https://bugzilla.suse.com/1038231 . SUSE Security Alert concerning samba: urgent patch addressing potential code execution vulnerability in SUSE Linux platforms. Advisory Identifier: SUSE-SU-2017:1391-1.. SUSE Linux,samba exploit,remote code execution. . Severity: Critical. LinuxSecurity.com Team
Updated samba packages that fix a security issue are now available for Red Hat Enterprise Linux 4.5 Extended Update Support. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: samba security update Advisory ID: RHSA-2008:0289-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2008:0289.html Issue date: 2008-05-28 CVE Names: CVE-2008-1105 ==================================================================== 1. Summary: Updated samba packages that fix a security issue are now available for Red Hat Enterprise Linux 4.5 Extended Update Support. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4.5.z - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux ES version 4.5.z - i386, ia64, x86_64 3. Description: Samba is a suite of programs used by machines to share files, printers, and other information. A heap-based buffer overflow flaw was found in the way Samba clients handle over-sized packets. If a client connected to a malicious Samba server, it was possible to execute arbitrary code as the Samba client user. It was also possible for a remote user to send a specially crafted print request to a Samba server that could result in the server executing the vulnerable client code, resulting in arbitrary code execution with the permissions of the Samba server. (CVE-2008-1105) Red Hat would like to thank Alin Rad Pop of Secunia Research for responsibly disclosing this issue. Users of Samba are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. 4. Solution: Before applying this update, make sure that allpreviously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 446724 - CVE-2008-1105 Samba client buffer overflow 6. Package List: Red Hat Enterprise Linux AS version 4.5.z: Source: i386: samba-3.0.10-2.el4_5.3.i386.rpm samba-client-3.0.10-2.el4_5.3.i386.rpm samba-common-3.0.10-2.el4_5.3.i386.rpm samba-debuginfo-3.0.10-2.el4_5.3.i386.rpm samba-swat-3.0.10-2.el4_5.3.i386.rpm ia64: samba-3.0.10-2.el4_5.3.ia64.rpm samba-client-3.0.10-2.el4_5.3.ia64.rpm samba-common-3.0.10-2.el4_5.3.i386.rpm samba-common-3.0.10-2.el4_5.3.ia64.rpm samba-debuginfo-3.0.10-2.el4_5.3.i386.rpm samba-debuginfo-3.0.10-2.el4_5.3.ia64.rpm samba-swat-3.0.10-2.el4_5.3.ia64.rpm ppc: samba-3.0.10-2.el4_5.3.ppc.rpm samba-client-3.0.10-2.el4_5.3.ppc.rpm samba-common-3.0.10-2.el4_5.3.ppc.rpm samba-common-3.0.10-2.el4_5.3.ppc64.rpm samba-debuginfo-3.0.10-2.el4_5.3.ppc.rpm samba-debuginfo-3.0.10-2.el4_5.3.ppc64.rpm samba-swat-3.0.10-2.el4_5.3.ppc.rpm s390: samba-3.0.10-2.el4_5.3.s390.rpm samba-client-3.0.10-2.el4_5.3.s390.rpm samba-common-3.0.10-2.el4_5.3.s390.rpm samba-debuginfo-3.0.10-2.el4_5.3.s390.rpm samba-swat-3.0.10-2.el4_5.3.s390.rpm s390x: samba-3.0.10-2.el4_5.3.s390x.rpm samba-client-3.0.10-2.el4_5.3.s390x.rpm samba-common-3.0.10-2.el4_5.3.s390.rpm samba-common-3.0.10-2.el4_5.3.s390x.rpm samba-debuginfo-3.0.10-2.el4_5.3.s390.rpm samba-debuginfo-3.0.10-2.el4_5.3.s390x.rpm samba-swat-3.0.10-2.el4_5.3.s390x.rpm x86_64: samba-3.0.10-2.el4_5.3.x86_64.rpm samba-client-3.0.10-2.el4_5.3.x86_64.rpm samba-common-3.0.10-2.el4_5.3.i386.rpm samba-common-3.0.10-2.el4_5.3.x86_64.rpm samba-debuginfo-3.0.10-2.el4_5.3.i386.rpm samba-debuginfo-3.0.10-2.el4_5.3.x86_64.rpm samba-swat-3.0.10-2.el4_5.3.x86_64.rpm Red Hat Enterprise Linux ES version4.5.z: Source: i386: samba-3.0.10-2.el4_5.3.i386.rpm samba-client-3.0.10-2.el4_5.3.i386.rpm samba-common-3.0.10-2.el4_5.3.i386.rpm samba-debuginfo-3.0.10-2.el4_5.3.i386.rpm samba-swat-3.0.10-2.el4_5.3.i386.rpm ia64: samba-3.0.10-2.el4_5.3.ia64.rpm samba-client-3.0.10-2.el4_5.3.ia64.rpm samba-common-3.0.10-2.el4_5.3.i386.rpm samba-common-3.0.10-2.el4_5.3.ia64.rpm samba-debuginfo-3.0.10-2.el4_5.3.i386.rpm samba-debuginfo-3.0.10-2.el4_5.3.ia64.rpm samba-swat-3.0.10-2.el4_5.3.ia64.rpm x86_64: samba-3.0.10-2.el4_5.3.x86_64.rpm samba-client-3.0.10-2.el4_5.3.x86_64.rpm samba-common-3.0.10-2.el4_5.3.i386.rpm samba-common-3.0.10-2.el4_5.3.x86_64.rpm samba-debuginfo-3.0.10-2.el4_5.3.i386.rpm samba-debuginfo-3.0.10-2.el4_5.3.x86_64.rpm samba-swat-3.0.10-2.el4_5.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-1105 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2008 Red Hat, Inc. . Important release for Samba tackling memory safety vulnerabilities in Red Hat platforms to improve protection and performance.. Security Patches, Samba Update, Critical Security Updates. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.