Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
199

CentOS: CESA-2017-3278 Urgent Security Update for Samba4 Released

Upstream details at : https://access.redhat.com/errata/RHSA-2017:3278. CentOS Errata and Security Advisory 2017:3278 Important Upstream details at : https://access.redhat.com/errata/RHSA-2017:3278 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: 7d9829553295a968d06bb84eae803714038365e64b7f9d8051689aa4ff442c48 samba4-4.2.10-12.el6_9.i686.rpm 3a872107613ff75a7028438c2cb89b9c95e47b9b40606eec7a35476ba040f201 samba4-client-4.2.10-12.el6_9.i686.rpm 91c72a494e0d15d912d933360cc5228be79701d64d610ecd25f835ebcfe32686 samba4-common-4.2.10-12.el6_9.i686.rpm d9c01b0229ded2cc7a8584f0853454b38599315e6cb6222c6fe9fc5f1030a8cd samba4-dc-4.2.10-12.el6_9.i686.rpm 2de0def968af53478f22312a978832293c16abebb0fba832e0891def67cc0b4f samba4-dc-libs-4.2.10-12.el6_9.i686.rpm 1a68772a35214e87a1ae86657c951f00388a405925f590aa17d3064876cc0e38 samba4-devel-4.2.10-12.el6_9.i686.rpm 49350c8b86c3afb56e68341b65174b6cb71f2df5d4a9f32fa18f1b1dae06826c samba4-libs-4.2.10-12.el6_9.i686.rpm 02994c04b40fb1c3562618e3e77b2aa6b11ee2cd32e5d0abd7d6885bdc8cc10e samba4-pidl-4.2.10-12.el6_9.i686.rpm 7e4f3d3ac219ee50100fbad8ef7cba3722bbfcd5e522f8fda89da492429eddb1 samba4-python-4.2.10-12.el6_9.i686.rpm 862adc0c52318d7db17e635b5f740591734440c469f6510ba991cecba4881770 samba4-test-4.2.10-12.el6_9.i686.rpm 2b7198f251f01d4a644fd555af9d713f431591e4a709653a3fb422341ebf47c5 samba4-winbind-4.2.10-12.el6_9.i686.rpm efbc1b1ae4eca6b07298803bcd76acf9782fc481e7d2d974203ab82c3ea23715 samba4-winbind-clients-4.2.10-12.el6_9.i686.rpm 1debf9ff0842214b215f69aa55ecf8749932597a98be0e2d4e61118d61334917 samba4-winbind-krb5-locator-4.2.10-12.el6_9.i686.rpm x86_64: a23a735bfd9f91fec7481ead3b7f737a7e9e4347dac578296286a2b80063c036 samba4-4.2.10-12.el6_9.x86_64.rpm 259a8998395281abe2c1b58a6df1923f18f43525bb6b9f46ef115c06c9227ede samba4-client-4.2.10-12.el6_9.x86_64.rpm 80dfbabbcb725bf9f0527dd695dfbae3ef85df560d695a9028e6de4816d683dc samba4-common-4.2.10-12.el6_9.x86_64.rpm 88ef55eb07690a64ac9c7b8313bb781332b9d0d530299b60f7cacaa61a7de9b8 samba4-dc-4.2.10-12.el6_9.x86_64.rpm a41cca312a313d6897c65e6be15e1e5cf07cbccfbed2469f3dc8411ec18a6001 samba4-dc-libs-4.2.10-12.el6_9.x86_64.rpm 68ae710292c856a7f037ddc9497c412cb6d83f1e1751c034a79a97f4e19817f2 samba4-devel-4.2.10-12.el6_9.x86_64.rpm b54adbd7416b8f4defb69a2a9437ef720b96e0d388cea45fa31c7fc62e55fad0 samba4-libs-4.2.10-12.el6_9.x86_64.rpm 8b2342c31200dedd48f4b3f8663b0ebc8f36ea79ba83bac30f733545440be7f5 samba4-pidl-4.2.10-12.el6_9.x86_64.rpm aac0d607a823792673f9d382d67359684f0512f1fb866f9fdb6c8ae9ff7da4df samba4-python-4.2.10-12.el6_9.x86_64.rpm e12fa88c49c8d9a52c2566afc61d0010c0fdaa17c558ef2b5ad212782cbd401a samba4-test-4.2.10-12.el6_9.x86_64.rpm f9247caaea35acdef7263627f55bbe1216764538e0ca0aa34493269f965eda3e samba4-winbind-4.2.10-12.el6_9.x86_64.rpm 53c527825df823b3a7aee472a3af154d4ebb2bbe0275485745dbd7fba5bfd22e samba4-winbind-clients-4.2.10-12.el6_9.x86_64.rpm 0bec2014a8c69d09c793d73d67e0f1df19d1005012e9577b4fc1e44388a57323 samba4-winbind-krb5-locator-4.2.10-12.el6_9.x86_64.rpm Source: 510d133515ab5e041ca4a00df1074ac2725cc6c45b573ddcbaf112959fbb1284 samba4-4.2.10-12.el6_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Key security notice for CentOS 6 samba4 regarding severe vulnerabilities and outlining essential patches.. CentOS 6, Samba4, Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 29, 2017 Important CentOS
200

Scientific Linux 6: SLSA-2017-3278-1 Critical: Samba4 Code Execution

A use-after-free flaw was found in the way samba servers handled certain SMB1 requests. An unauthenticated attacker could send specially-crafted SMB1 requests to cause the server to crash or execute arbitrary code. (CVE-2017-14746) * A memory disclosure flaw was found in samba. An attacker could retrieve parts of server memory, which could contain potentially sensitive data, by sending specia [More...]. Synopsis: Important: samba4 security update Advisory ID: SLSA-2017:3278-1 Issue Date: 2017-11-29 CVE Numbers: CVE-2017-14746 CVE-2017-15275 -- Security Fix(es): * A use-after-free flaw was found in the way samba servers handled certain SMB1 requests. An unauthenticated attacker could send specially-crafted SMB1 requests to cause the server to crash or execute arbitrary code. (CVE-2017-14746) * A memory disclosure flaw was found in samba. An attacker could retrieve parts of server memory, which could contain potentially sensitive data, by sending specially-crafted requests to the samba server. (CVE-2017-15275) -- SL6 x86_64 samba4-4.2.10-12.el6_9.x86_64.rpm samba4-client-4.2.10-12.el6_9.x86_64.rpm samba4-common-4.2.10-12.el6_9.x86_64.rpm samba4-dc-4.2.10-12.el6_9.x86_64.rpm samba4-dc-libs-4.2.10-12.el6_9.x86_64.rpm samba4-debuginfo-4.2.10-12.el6_9.x86_64.rpm samba4-devel-4.2.10-12.el6_9.x86_64.rpm samba4-libs-4.2.10-12.el6_9.x86_64.rpm samba4-pidl-4.2.10-12.el6_9.x86_64.rpm samba4-python-4.2.10-12.el6_9.x86_64.rpm samba4-test-4.2.10-12.el6_9.x86_64.rpm samba4-winbind-4.2.10-12.el6_9.x86_64.rpm samba4-winbind-clients-4.2.10-12.el6_9.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-12.el6_9.x86_64.rpm i386 samba4-4.2.10-12.el6_9.i686.rpm samba4-client-4.2.10-12.el6_9.i686.rpm samba4-common-4.2.10-12.el6_9.i686.rpm samba4-dc-4.2.10-12.el6_9.i686.rpm samba4-dc-libs-4.2.10-12.el6_9.i686.rpm samba4-debuginfo-4.2.10-12.el6_9.i686.rpm samba4-devel-4.2.10-12.el6_9.i686.rpm samba4-libs-4.2.10-12.el6_9.i686.rpm samba4-pidl-4.2.10-12.el6_9.i686.rpm samba4-python-4.2.10-12.el6_9.i686.rpm samba4-test-4.2.10-12.el6_9.i686.rpm samba4-winbind-4.2.10-12.el6_9.i686.rpm samba4-winbind-clients-4.2.10-12.el6_9.i686.rpm samba4-winbind-krb5-locator-4.2.10-12.el6_9.i686.rpm - Scientific Linux Development Team . Urgent samba4 patch released tackling use-after-free and memory leak vulnerabilities in SL6.x setups.. samba4 security, SL6 update, code execution risk, memory disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 29, 2017 Critical Scientific Linux
98

Red Hat Enterprise Linux: RHSA-2017:0744 Moderate: Samba4 Security Update

An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: samba4 security and bug fix update Advisory ID: RHSA-2017:0744-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2017:0744.html Issue date: 2017-03-21 CVE Names: CVE-2016-2125 CVE-2016-2126 ==================================================================== 1. Summary: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information. Security Fix(es): * It was found that Samba always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users. (CVE-2016-2125) * A flaw was found in the way Samba handled PAC (Privilege Attribute Certificate) checksums. Aremote, authenticated attacker could use this flaw to crash the winbindd process. (CVE-2016-2126) Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the smb service will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1403114 - CVE-2016-2125 samba: Unconditional privilege delegation to Kerberos servers in trusted realms 1403115 - CVE-2016-2126 samba: Flaws in Kerberos PAC validation can trigger privilege elevation 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: samba4-4.2.10-9.el6.src.rpm i386: samba4-4.2.10-9.el6.i686.rpm samba4-client-4.2.10-9.el6.i686.rpm samba4-common-4.2.10-9.el6.i686.rpm samba4-dc-4.2.10-9.el6.i686.rpm samba4-dc-libs-4.2.10-9.el6.i686.rpm samba4-debuginfo-4.2.10-9.el6.i686.rpm samba4-devel-4.2.10-9.el6.i686.rpm samba4-libs-4.2.10-9.el6.i686.rpm samba4-pidl-4.2.10-9.el6.i686.rpm samba4-python-4.2.10-9.el6.i686.rpm samba4-test-4.2.10-9.el6.i686.rpm samba4-winbind-4.2.10-9.el6.i686.rpm samba4-winbind-clients-4.2.10-9.el6.i686.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.i686.rpm x86_64: samba4-4.2.10-9.el6.x86_64.rpm samba4-client-4.2.10-9.el6.x86_64.rpm samba4-common-4.2.10-9.el6.x86_64.rpm samba4-dc-4.2.10-9.el6.x86_64.rpm samba4-dc-libs-4.2.10-9.el6.x86_64.rpm samba4-debuginfo-4.2.10-9.el6.x86_64.rpm samba4-devel-4.2.10-9.el6.x86_64.rpm samba4-libs-4.2.10-9.el6.x86_64.rpm samba4-pidl-4.2.10-9.el6.x86_64.rpm samba4-python-4.2.10-9.el6.x86_64.rpm samba4-test-4.2.10-9.el6.x86_64.rpm samba4-winbind-4.2.10-9.el6.x86_64.rpm samba4-winbind-clients-4.2.10-9.el6.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.x86_64.rpm Red Hat Enterprise Linux HPC Node (v.6): Source: samba4-4.2.10-9.el6.src.rpm x86_64: samba4-4.2.10-9.el6.x86_64.rpm samba4-client-4.2.10-9.el6.x86_64.rpm samba4-common-4.2.10-9.el6.x86_64.rpm samba4-dc-4.2.10-9.el6.x86_64.rpm samba4-dc-libs-4.2.10-9.el6.x86_64.rpm samba4-debuginfo-4.2.10-9.el6.x86_64.rpm samba4-devel-4.2.10-9.el6.x86_64.rpm samba4-libs-4.2.10-9.el6.x86_64.rpm samba4-pidl-4.2.10-9.el6.x86_64.rpm samba4-python-4.2.10-9.el6.x86_64.rpm samba4-test-4.2.10-9.el6.x86_64.rpm samba4-winbind-4.2.10-9.el6.x86_64.rpm samba4-winbind-clients-4.2.10-9.el6.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: samba4-4.2.10-9.el6.src.rpm i386: samba4-4.2.10-9.el6.i686.rpm samba4-client-4.2.10-9.el6.i686.rpm samba4-common-4.2.10-9.el6.i686.rpm samba4-dc-4.2.10-9.el6.i686.rpm samba4-dc-libs-4.2.10-9.el6.i686.rpm samba4-debuginfo-4.2.10-9.el6.i686.rpm samba4-devel-4.2.10-9.el6.i686.rpm samba4-libs-4.2.10-9.el6.i686.rpm samba4-pidl-4.2.10-9.el6.i686.rpm samba4-python-4.2.10-9.el6.i686.rpm samba4-test-4.2.10-9.el6.i686.rpm samba4-winbind-4.2.10-9.el6.i686.rpm samba4-winbind-clients-4.2.10-9.el6.i686.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.i686.rpm ppc64: samba4-4.2.10-9.el6.ppc64.rpm samba4-client-4.2.10-9.el6.ppc64.rpm samba4-common-4.2.10-9.el6.ppc64.rpm samba4-dc-4.2.10-9.el6.ppc64.rpm samba4-dc-libs-4.2.10-9.el6.ppc64.rpm samba4-debuginfo-4.2.10-9.el6.ppc64.rpm samba4-devel-4.2.10-9.el6.ppc64.rpm samba4-libs-4.2.10-9.el6.ppc64.rpm samba4-pidl-4.2.10-9.el6.ppc64.rpm samba4-python-4.2.10-9.el6.ppc64.rpm samba4-test-4.2.10-9.el6.ppc64.rpm samba4-winbind-4.2.10-9.el6.ppc64.rpm samba4-winbind-clients-4.2.10-9.el6.ppc64.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.ppc64.rpm s390x: samba4-4.2.10-9.el6.s390x.rpm samba4-client-4.2.10-9.el6.s390x.rpm samba4-common-4.2.10-9.el6.s390x.rpm samba4-dc-4.2.10-9.el6.s390x.rpm samba4-dc-libs-4.2.10-9.el6.s390x.rpm samba4-debuginfo-4.2.10-9.el6.s390x.rpm samba4-devel-4.2.10-9.el6.s390x.rpm samba4-libs-4.2.10-9.el6.s390x.rpm samba4-pidl-4.2.10-9.el6.s390x.rpm samba4-python-4.2.10-9.el6.s390x.rpm samba4-test-4.2.10-9.el6.s390x.rpm samba4-winbind-4.2.10-9.el6.s390x.rpm samba4-winbind-clients-4.2.10-9.el6.s390x.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.s390x.rpm x86_64: samba4-4.2.10-9.el6.x86_64.rpm samba4-client-4.2.10-9.el6.x86_64.rpm samba4-common-4.2.10-9.el6.x86_64.rpm samba4-dc-4.2.10-9.el6.x86_64.rpm samba4-dc-libs-4.2.10-9.el6.x86_64.rpm samba4-debuginfo-4.2.10-9.el6.x86_64.rpm samba4-devel-4.2.10-9.el6.x86_64.rpm samba4-libs-4.2.10-9.el6.x86_64.rpm samba4-pidl-4.2.10-9.el6.x86_64.rpm samba4-python-4.2.10-9.el6.x86_64.rpm samba4-test-4.2.10-9.el6.x86_64.rpm samba4-winbind-4.2.10-9.el6.x86_64.rpm samba4-winbind-clients-4.2.10-9.el6.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: samba4-4.2.10-9.el6.src.rpm i386: samba4-4.2.10-9.el6.i686.rpm samba4-client-4.2.10-9.el6.i686.rpm samba4-common-4.2.10-9.el6.i686.rpm samba4-dc-4.2.10-9.el6.i686.rpm samba4-dc-libs-4.2.10-9.el6.i686.rpm samba4-debuginfo-4.2.10-9.el6.i686.rpm samba4-devel-4.2.10-9.el6.i686.rpm samba4-libs-4.2.10-9.el6.i686.rpm samba4-pidl-4.2.10-9.el6.i686.rpm samba4-python-4.2.10-9.el6.i686.rpm samba4-test-4.2.10-9.el6.i686.rpm samba4-winbind-4.2.10-9.el6.i686.rpm samba4-winbind-clients-4.2.10-9.el6.i686.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.i686.rpm x86_64: samba4-4.2.10-9.el6.x86_64.rpm samba4-client-4.2.10-9.el6.x86_64.rpm samba4-common-4.2.10-9.el6.x86_64.rpm samba4-dc-4.2.10-9.el6.x86_64.rpm samba4-dc-libs-4.2.10-9.el6.x86_64.rpm samba4-debuginfo-4.2.10-9.el6.x86_64.rpm samba4-devel-4.2.10-9.el6.x86_64.rpm samba4-libs-4.2.10-9.el6.x86_64.rpm samba4-pidl-4.2.10-9.el6.x86_64.rpm samba4-python-4.2.10-9.el6.x86_64.rpm samba4-test-4.2.10-9.el6.x86_64.rpm samba4-winbind-4.2.10-9.el6.x86_64.rpm samba4-winbind-clients-4.2.10-9.el6.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-9.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-2125 https://access.redhat.com/security/cve/CVE-2016-2126 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/6.9_Release_Notes/index.html https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/6.9_Technical_Notes/index.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iD8DBQFY0PYDXlSAg2UNWIIRAuDlAKCyaEBSSXFP4FpwlPq2aeSqpX+DWQCeIjyE z92Fk6IIfEI0tGbw3EQZXQw=yv/o -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu provides a kernel patch to rectify vulnerabilities rated as moderate, bolstering system integrity.. Red Hat, Samba Update, Security Patch, Linux Security. . LinuxSecurity.com Team

Calendar%202 Mar 21, 2017 Red Hat
98

Red Hat 6.6 RHSA-2016:0620-01 Critical: Samba4 Security Update

An update for samba4 is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: samba4 security, bug fix, and enhancement update Advisory ID: RHSA-2016:0620-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:0620.html Issue date: 2016-04-12 CVE Names: CVE-2015-5370 CVE-2016-2110 CVE-2016-2111 CVE-2016-2112 CVE-2016-2113 CVE-2016-2114 CVE-2016-2115 CVE-2016-2118 ==================================================================== 1. Summary: An update for samba4 is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux HPC Node EUS (v. 6.6) - x86_64 Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.6) - x86_64 Red Hat Enterprise Linux Server AUS (v. 6.2) - x86_64 Red Hat Enterprise Linux Server AUS (v. 6.4) - x86_64 Red Hat Enterprise Linux Server AUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server EUS (v. 6.6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.2) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.4) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.5)- x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 6.6) - i386, ppc64, s390x, x86_64 3. Description: Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information. The following packages have been upgraded to a newer upstream version: Samba (4.2.10). Refer to the Release Notes listed in the References section for a complete list of changes. Security Fix(es): * Multiple flaws were found in Samba's DCE/RPC protocol implementation. A remote, authenticated attacker could use these flaws to cause a denial of service against the Samba server (high CPU load or a crash) or, possibly, execute arbitrary code with the permissions of the user running Samba (root). This flaw could also be used to downgrade a secure DCE/RPC connection by a man-in-the-middle attacker taking control of an Active Directory (AD) object and compromising the security of a Samba Active Directory Domain Controller (DC). (CVE-2015-5370) Note: While Samba packages as shipped in Red Hat Enterprise Linux do not support running Samba as an AD DC, this flaw applies to all roles Samba implements. * A protocol flaw, publicly referred to as Badlock, was found in the Security Account Manager Remote Protocol (MS-SAMR) and the Local Security Authority (Domain Policy) Remote Protocol (MS-LSAD). Any authenticated DCE/RPC connection that a client initiates against a server could be used by a man-in-the-middle attacker to impersonate the authenticated user against the SAMR or LSA service on the server. As a result, the attacker would be able to get read/write access to the Security Account Manager database, and use this to reveal all passwords or any other potentially sensitive information in that database. (CVE-2016-2118) * Several flaws were found in Samba's implementation of NTLMSSP authentication. An unauthenticated, man-in-the-middle attacker could use this flaw to clear the encryption and integrity flagsof a connection, causing data to be transmitted in plain text. The attacker could also force the client or server into sending data in plain text even if encryption was explicitly requested for that connection. (CVE-2016-2110) * It was discovered that Samba configured as a Domain Controller would establish a secure communication channel with a machine using a spoofed computer name. A remote attacker able to observe network traffic could use this flaw to obtain session-related information about the spoofed machine. (CVE-2016-2111) * It was found that Samba's LDAP implementation did not enforce integrity protection for LDAP connections. A man-in-the-middle attacker could use this flaw to downgrade LDAP connections to use no integrity protection, allowing them to hijack such connections. (CVE-2016-2112) * It was found that Samba did not validate SSL/TLS certificates in certain connections. A man-in-the-middle attacker could use this flaw to spoof a Samba server using a specially crafted SSL/TLS certificate. (CVE-2016-2113) * It was discovered that Samba did not enforce Server Message Block (SMB) signing for clients using the SMB1 protocol. A man-in-the-middle attacker could use this flaw to modify traffic between a client and a server. (CVE-2016-2114) * It was found that Samba did not enable integrity protection for IPC traffic by default. A man-in-the-middle attacker could use this flaw to view and modify the data sent between a Samba server and a client. (CVE-2016-2115) Red Hat would like to thank the Samba project for reporting these issues. Upstream acknowledges Jouni Knuutinen (Synopsis) as the original reporter of CVE-2015-5370; and Stefan Metzmacher (SerNet) as the original reporter of CVE-2016-2118, CVE-2016-2110, CVE-2016-2112, CVE-2016-2113, CVE-2016-2114, and CVE-2016-2115. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the smb service will berestarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1309987 - CVE-2015-5370 samba: crash in dcesrv_auth_bind_ack due to missing error check 1311893 - CVE-2016-2110 samba: Man-in-the-middle attacks possible with NTLMSSP authentication 1311902 - CVE-2016-2111 samba: Spoofing vulnerability when domain controller is configured 1311903 - CVE-2016-2112 samba: Missing downgrade detection 1311910 - CVE-2016-2113 samba: Server certificates not validated at client side 1312082 - CVE-2016-2114 samba: Samba based active directory domain controller does not enforce smb signing 1312084 - CVE-2016-2115 samba: Smb signing not required by default when smb client connection is used for ipc usage 1317990 - CVE-2016-2118 samba: SAMR and LSA man in the middle attacks 6. Package List: Red Hat Enterprise Linux HPC Node EUS (v. 6.6): Source: ipa-3.0.0-42.el6_6.1.src.rpm libldb-1.1.25-2.el6_6.src.rpm samba4-4.2.10-6.el6_6.src.rpm x86_64: ipa-client-3.0.0-42.el6_6.1.x86_64.rpm ipa-debuginfo-3.0.0-42.el6_6.1.x86_64.rpm ipa-python-3.0.0-42.el6_6.1.x86_64.rpm libldb-1.1.25-2.el6_6.i686.rpm libldb-1.1.25-2.el6_6.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_6.i686.rpm libldb-debuginfo-1.1.25-2.el6_6.x86_64.rpm libldb-devel-1.1.25-2.el6_6.i686.rpm libldb-devel-1.1.25-2.el6_6.x86_64.rpm pyldb-1.1.25-2.el6_6.x86_64.rpm samba4-4.2.10-6.el6_6.x86_64.rpm samba4-client-4.2.10-6.el6_6.x86_64.rpm samba4-common-4.2.10-6.el6_6.x86_64.rpm samba4-dc-4.2.10-6.el6_6.x86_64.rpm samba4-dc-libs-4.2.10-6.el6_6.x86_64.rpm samba4-debuginfo-4.2.10-6.el6_6.x86_64.rpm samba4-devel-4.2.10-6.el6_6.x86_64.rpm samba4-libs-4.2.10-6.el6_6.x86_64.rpm samba4-pidl-4.2.10-6.el6_6.x86_64.rpm samba4-python-4.2.10-6.el6_6.x86_64.rpm samba4-test-4.2.10-6.el6_6.x86_64.rpm samba4-winbind-4.2.10-6.el6_6.x86_64.rpm samba4-winbind-clients-4.2.10-6.el6_6.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-6.el6_6.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional EUS (v.6.6): x86_64: ipa-admintools-3.0.0-42.el6_6.1.x86_64.rpm ipa-debuginfo-3.0.0-42.el6_6.1.x86_64.rpm ipa-server-3.0.0-42.el6_6.1.x86_64.rpm ipa-server-selinux-3.0.0-42.el6_6.1.x86_64.rpm ipa-server-trust-ad-3.0.0-42.el6_6.1.x86_64.rpm ldb-tools-1.1.25-2.el6_6.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_6.x86_64.rpm pyldb-devel-1.1.25-2.el6_6.x86_64.rpm Red Hat Enterprise Linux Server AUS (v. 6.2): Source: libldb-1.1.25-2.el6_2.src.rpm sssd-1.5.1-66.el6_2.5.src.rpm x86_64: libipa_hbac-1.5.1-66.el6_2.5.i686.rpm libipa_hbac-1.5.1-66.el6_2.5.x86_64.rpm libipa_hbac-python-1.5.1-66.el6_2.5.x86_64.rpm libldb-1.1.25-2.el6_2.i686.rpm libldb-1.1.25-2.el6_2.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_2.i686.rpm libldb-debuginfo-1.1.25-2.el6_2.x86_64.rpm libldb-devel-1.1.25-2.el6_2.i686.rpm libldb-devel-1.1.25-2.el6_2.x86_64.rpm pyldb-1.1.25-2.el6_2.x86_64.rpm sssd-1.5.1-66.el6_2.5.x86_64.rpm sssd-client-1.5.1-66.el6_2.5.i686.rpm sssd-client-1.5.1-66.el6_2.5.x86_64.rpm sssd-debuginfo-1.5.1-66.el6_2.5.i686.rpm sssd-debuginfo-1.5.1-66.el6_2.5.x86_64.rpm Red Hat Enterprise Linux Server AUS (v.6.4): Source: ipa-3.0.0-26.el6_4.5.src.rpm libldb-1.1.25-2.el6_4.src.rpm samba4-4.2.10-6.el6_4.src.rpm sssd-1.9.2-82.12.el6_4.src.rpm x86_64: ipa-admintools-3.0.0-26.el6_4.5.x86_64.rpm ipa-client-3.0.0-26.el6_4.5.x86_64.rpm ipa-debuginfo-3.0.0-26.el6_4.5.x86_64.rpm ipa-python-3.0.0-26.el6_4.5.x86_64.rpm ipa-server-3.0.0-26.el6_4.5.x86_64.rpm ipa-server-selinux-3.0.0-26.el6_4.5.x86_64.rpm ipa-server-trust-ad-3.0.0-26.el6_4.5.x86_64.rpm libipa_hbac-1.9.2-82.12.el6_4.i686.rpm libipa_hbac-1.9.2-82.12.el6_4.x86_64.rpm libipa_hbac-python-1.9.2-82.12.el6_4.x86_64.rpm libldb-1.1.25-2.el6_4.i686.rpm libldb-1.1.25-2.el6_4.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_4.i686.rpm libldb-debuginfo-1.1.25-2.el6_4.x86_64.rpm libldb-devel-1.1.25-2.el6_4.i686.rpm libldb-devel-1.1.25-2.el6_4.x86_64.rpm libsss_autofs-1.9.2-82.12.el6_4.x86_64.rpm libsss_idmap-1.9.2-82.12.el6_4.i686.rpm libsss_idmap-1.9.2-82.12.el6_4.x86_64.rpm libsss_sudo-1.9.2-82.12.el6_4.x86_64.rpm pyldb-1.1.25-2.el6_4.x86_64.rpm samba4-4.2.10-6.el6_4.x86_64.rpm samba4-client-4.2.10-6.el6_4.x86_64.rpm samba4-common-4.2.10-6.el6_4.x86_64.rpm samba4-dc-4.2.10-6.el6_4.x86_64.rpm samba4-dc-libs-4.2.10-6.el6_4.x86_64.rpm samba4-debuginfo-4.2.10-6.el6_4.x86_64.rpm samba4-devel-4.2.10-6.el6_4.x86_64.rpm samba4-libs-4.2.10-6.el6_4.x86_64.rpm samba4-pidl-4.2.10-6.el6_4.x86_64.rpm samba4-python-4.2.10-6.el6_4.x86_64.rpm samba4-test-4.2.10-6.el6_4.x86_64.rpm samba4-winbind-4.2.10-6.el6_4.x86_64.rpm samba4-winbind-clients-4.2.10-6.el6_4.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-6.el6_4.x86_64.rpm sssd-1.9.2-82.12.el6_4.x86_64.rpm sssd-client-1.9.2-82.12.el6_4.i686.rpm sssd-client-1.9.2-82.12.el6_4.x86_64.rpm sssd-debuginfo-1.9.2-82.12.el6_4.i686.rpm sssd-debuginfo-1.9.2-82.12.el6_4.x86_64.rpm Red Hat Enterprise Linux Server AUS (v.6.5): Source: ipa-3.0.0-37.el6_5.1.src.rpm libldb-1.1.25-2.el6_5.src.rpm samba4-4.2.10-6.el6_5.src.rpm sssd-1.9.2-129.el6_5.7.src.rpm x86_64: ipa-admintools-3.0.0-37.el6_5.1.x86_64.rpm ipa-client-3.0.0-37.el6_5.1.x86_64.rpm ipa-debuginfo-3.0.0-37.el6_5.1.x86_64.rpm ipa-python-3.0.0-37.el6_5.1.x86_64.rpm ipa-server-3.0.0-37.el6_5.1.x86_64.rpm ipa-server-selinux-3.0.0-37.el6_5.1.x86_64.rpm ipa-server-trust-ad-3.0.0-37.el6_5.1.x86_64.rpm libipa_hbac-1.9.2-129.el6_5.7.i686.rpm libipa_hbac-1.9.2-129.el6_5.7.x86_64.rpm libipa_hbac-python-1.9.2-129.el6_5.7.x86_64.rpm libldb-1.1.25-2.el6_5.i686.rpm libldb-1.1.25-2.el6_5.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_5.i686.rpm libldb-debuginfo-1.1.25-2.el6_5.x86_64.rpm libldb-devel-1.1.25-2.el6_5.i686.rpm libldb-devel-1.1.25-2.el6_5.x86_64.rpm libsss_autofs-1.9.2-129.el6_5.7.x86_64.rpm libsss_idmap-1.9.2-129.el6_5.7.i686.rpm libsss_idmap-1.9.2-129.el6_5.7.x86_64.rpm libsss_sudo-1.9.2-129.el6_5.7.x86_64.rpm pyldb-1.1.25-2.el6_5.x86_64.rpm samba4-4.2.10-6.el6_5.x86_64.rpm samba4-client-4.2.10-6.el6_5.x86_64.rpm samba4-common-4.2.10-6.el6_5.x86_64.rpm samba4-dc-4.2.10-6.el6_5.x86_64.rpm samba4-dc-libs-4.2.10-6.el6_5.x86_64.rpm samba4-debuginfo-4.2.10-6.el6_5.x86_64.rpm samba4-devel-4.2.10-6.el6_5.x86_64.rpm samba4-libs-4.2.10-6.el6_5.x86_64.rpm samba4-pidl-4.2.10-6.el6_5.x86_64.rpm samba4-python-4.2.10-6.el6_5.x86_64.rpm samba4-test-4.2.10-6.el6_5.x86_64.rpm samba4-winbind-4.2.10-6.el6_5.x86_64.rpm samba4-winbind-clients-4.2.10-6.el6_5.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-6.el6_5.x86_64.rpm sssd-1.9.2-129.el6_5.7.x86_64.rpm sssd-client-1.9.2-129.el6_5.7.i686.rpm sssd-client-1.9.2-129.el6_5.7.x86_64.rpm sssd-debuginfo-1.9.2-129.el6_5.7.i686.rpm sssd-debuginfo-1.9.2-129.el6_5.7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.6.6): Source: ipa-3.0.0-42.el6_6.1.src.rpm libldb-1.1.25-2.el6_6.src.rpm samba4-4.2.10-6.el6_6.src.rpm i386: ipa-admintools-3.0.0-42.el6_6.1.i686.rpm ipa-client-3.0.0-42.el6_6.1.i686.rpm ipa-debuginfo-3.0.0-42.el6_6.1.i686.rpm ipa-python-3.0.0-42.el6_6.1.i686.rpm ipa-server-3.0.0-42.el6_6.1.i686.rpm ipa-server-selinux-3.0.0-42.el6_6.1.i686.rpm ipa-server-trust-ad-3.0.0-42.el6_6.1.i686.rpm libldb-1.1.25-2.el6_6.i686.rpm libldb-debuginfo-1.1.25-2.el6_6.i686.rpm libldb-devel-1.1.25-2.el6_6.i686.rpm pyldb-1.1.25-2.el6_6.i686.rpm samba4-4.2.10-6.el6_6.i686.rpm samba4-client-4.2.10-6.el6_6.i686.rpm samba4-common-4.2.10-6.el6_6.i686.rpm samba4-dc-4.2.10-6.el6_6.i686.rpm samba4-dc-libs-4.2.10-6.el6_6.i686.rpm samba4-debuginfo-4.2.10-6.el6_6.i686.rpm samba4-devel-4.2.10-6.el6_6.i686.rpm samba4-libs-4.2.10-6.el6_6.i686.rpm samba4-pidl-4.2.10-6.el6_6.i686.rpm samba4-python-4.2.10-6.el6_6.i686.rpm samba4-test-4.2.10-6.el6_6.i686.rpm samba4-winbind-4.2.10-6.el6_6.i686.rpm samba4-winbind-clients-4.2.10-6.el6_6.i686.rpm samba4-winbind-krb5-locator-4.2.10-6.el6_6.i686.rpm ppc64: ipa-admintools-3.0.0-42.el6_6.1.ppc64.rpm ipa-client-3.0.0-42.el6_6.1.ppc64.rpm ipa-debuginfo-3.0.0-42.el6_6.1.ppc64.rpm ipa-python-3.0.0-42.el6_6.1.ppc64.rpm libldb-1.1.25-2.el6_6.ppc.rpm libldb-1.1.25-2.el6_6.ppc64.rpm libldb-debuginfo-1.1.25-2.el6_6.ppc.rpm libldb-debuginfo-1.1.25-2.el6_6.ppc64.rpm libldb-devel-1.1.25-2.el6_6.ppc.rpm libldb-devel-1.1.25-2.el6_6.ppc64.rpm pyldb-1.1.25-2.el6_6.ppc64.rpm samba4-4.2.10-6.el6_6.ppc64.rpm samba4-client-4.2.10-6.el6_6.ppc64.rpm samba4-common-4.2.10-6.el6_6.ppc64.rpm samba4-dc-4.2.10-6.el6_6.ppc64.rpm samba4-dc-libs-4.2.10-6.el6_6.ppc64.rpm samba4-debuginfo-4.2.10-6.el6_6.ppc64.rpm samba4-devel-4.2.10-6.el6_6.ppc64.rpm samba4-libs-4.2.10-6.el6_6.ppc64.rpm samba4-pidl-4.2.10-6.el6_6.ppc64.rpm samba4-python-4.2.10-6.el6_6.ppc64.rpm samba4-test-4.2.10-6.el6_6.ppc64.rpm samba4-winbind-4.2.10-6.el6_6.ppc64.rpm samba4-winbind-clients-4.2.10-6.el6_6.ppc64.rpm samba4-winbind-krb5-locator-4.2.10-6.el6_6.ppc64.rpm s390x: ipa-admintools-3.0.0-42.el6_6.1.s390x.rpm ipa-client-3.0.0-42.el6_6.1.s390x.rpm ipa-debuginfo-3.0.0-42.el6_6.1.s390x.rpm ipa-python-3.0.0-42.el6_6.1.s390x.rpm libldb-1.1.25-2.el6_6.s390.rpm libldb-1.1.25-2.el6_6.s390x.rpm libldb-debuginfo-1.1.25-2.el6_6.s390.rpm libldb-debuginfo-1.1.25-2.el6_6.s390x.rpm libldb-devel-1.1.25-2.el6_6.s390.rpm libldb-devel-1.1.25-2.el6_6.s390x.rpm pyldb-1.1.25-2.el6_6.s390x.rpm samba4-4.2.10-6.el6_6.s390x.rpm samba4-client-4.2.10-6.el6_6.s390x.rpm samba4-common-4.2.10-6.el6_6.s390x.rpm samba4-dc-4.2.10-6.el6_6.s390x.rpm samba4-dc-libs-4.2.10-6.el6_6.s390x.rpm samba4-debuginfo-4.2.10-6.el6_6.s390x.rpm samba4-devel-4.2.10-6.el6_6.s390x.rpm samba4-libs-4.2.10-6.el6_6.s390x.rpm samba4-pidl-4.2.10-6.el6_6.s390x.rpm samba4-python-4.2.10-6.el6_6.s390x.rpm samba4-test-4.2.10-6.el6_6.s390x.rpm samba4-winbind-4.2.10-6.el6_6.s390x.rpm samba4-winbind-clients-4.2.10-6.el6_6.s390x.rpm samba4-winbind-krb5-locator-4.2.10-6.el6_6.s390x.rpm x86_64: ipa-admintools-3.0.0-42.el6_6.1.x86_64.rpm ipa-client-3.0.0-42.el6_6.1.x86_64.rpm ipa-debuginfo-3.0.0-42.el6_6.1.x86_64.rpm ipa-python-3.0.0-42.el6_6.1.x86_64.rpm ipa-server-3.0.0-42.el6_6.1.x86_64.rpm ipa-server-selinux-3.0.0-42.el6_6.1.x86_64.rpm ipa-server-trust-ad-3.0.0-42.el6_6.1.x86_64.rpm libldb-1.1.25-2.el6_6.i686.rpm libldb-1.1.25-2.el6_6.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_6.i686.rpm libldb-debuginfo-1.1.25-2.el6_6.x86_64.rpm libldb-devel-1.1.25-2.el6_6.i686.rpm libldb-devel-1.1.25-2.el6_6.x86_64.rpm pyldb-1.1.25-2.el6_6.x86_64.rpm samba4-4.2.10-6.el6_6.x86_64.rpm samba4-client-4.2.10-6.el6_6.x86_64.rpm samba4-common-4.2.10-6.el6_6.x86_64.rpm samba4-dc-4.2.10-6.el6_6.x86_64.rpm samba4-dc-libs-4.2.10-6.el6_6.x86_64.rpm samba4-debuginfo-4.2.10-6.el6_6.x86_64.rpm samba4-devel-4.2.10-6.el6_6.x86_64.rpm samba4-libs-4.2.10-6.el6_6.x86_64.rpm samba4-pidl-4.2.10-6.el6_6.x86_64.rpm samba4-python-4.2.10-6.el6_6.x86_64.rpm samba4-test-4.2.10-6.el6_6.x86_64.rpm samba4-winbind-4.2.10-6.el6_6.x86_64.rpm samba4-winbind-clients-4.2.10-6.el6_6.x86_64.rpm samba4-winbind-krb5-locator-4.2.10-6.el6_6.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 6.2): Source: evolution-mapi-0.28.3-8.el6_2.src.rpm libldb-1.1.25-2.el6_2.src.rpm openchange-1.0-1.el6_2.src.rpm samba4-4.2.10-6.el6_2.src.rpm sssd-1.5.1-66.el6_2.5.src.rpm x86_64: evolution-mapi-0.28.3-8.el6_2.i686.rpm evolution-mapi-0.28.3-8.el6_2.x86_64.rpm evolution-mapi-debuginfo-0.28.3-8.el6_2.i686.rpm evolution-mapi-debuginfo-0.28.3-8.el6_2.x86_64.rpm evolution-mapi-devel-0.28.3-8.el6_2.i686.rpm evolution-mapi-devel-0.28.3-8.el6_2.x86_64.rpm ldb-tools-1.1.25-2.el6_2.x86_64.rpm libipa_hbac-devel-1.5.1-66.el6_2.5.i686.rpm libipa_hbac-devel-1.5.1-66.el6_2.5.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_2.i686.rpm libldb-debuginfo-1.1.25-2.el6_2.x86_64.rpm libldb-devel-1.1.25-2.el6_2.i686.rpm libldb-devel-1.1.25-2.el6_2.x86_64.rpm openchange-1.0-1.el6_2.i686.rpm openchange-1.0-1.el6_2.x86_64.rpm openchange-client-1.0-1.el6_2.x86_64.rpm openchange-debuginfo-1.0-1.el6_2.i686.rpm openchange-debuginfo-1.0-1.el6_2.x86_64.rpm openchange-devel-1.0-1.el6_2.i686.rpm openchange-devel-1.0-1.el6_2.x86_64.rpm openchange-devel-docs-1.0-1.el6_2.x86_64.rpm pyldb-devel-1.1.25-2.el6_2.x86_64.rpm samba4-4.2.10-6.el6_2.x86_64.rpm samba4-debuginfo-4.2.10-6.el6_2.i686.rpm samba4-debuginfo-4.2.10-6.el6_2.x86_64.rpm samba4-devel-4.2.10-6.el6_2.i686.rpm samba4-devel-4.2.10-6.el6_2.x86_64.rpm samba4-libs-4.2.10-6.el6_2.i686.rpm samba4-libs-4.2.10-6.el6_2.x86_64.rpm samba4-pidl-4.2.10-6.el6_2.x86_64.rpm sssd-debuginfo-1.5.1-66.el6_2.5.i686.rpm sssd-debuginfo-1.5.1-66.el6_2.5.x86_64.rpm sssd-tools-1.5.1-66.el6_2.5.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v.6.4): Source: libldb-1.1.25-2.el6_4.src.rpm openchange-1.0-5.el6_4.src.rpm sssd-1.9.2-82.12.el6_4.src.rpm x86_64: ldb-tools-1.1.25-2.el6_4.x86_64.rpm libipa_hbac-devel-1.9.2-82.12.el6_4.i686.rpm libipa_hbac-devel-1.9.2-82.12.el6_4.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_4.x86_64.rpm libsss_idmap-devel-1.9.2-82.12.el6_4.i686.rpm libsss_idmap-devel-1.9.2-82.12.el6_4.x86_64.rpm libsss_sudo-devel-1.9.2-82.12.el6_4.i686.rpm libsss_sudo-devel-1.9.2-82.12.el6_4.x86_64.rpm openchange-1.0-5.el6_4.x86_64.rpm openchange-client-1.0-5.el6_4.x86_64.rpm openchange-debuginfo-1.0-5.el6_4.x86_64.rpm openchange-devel-1.0-5.el6_4.x86_64.rpm openchange-devel-docs-1.0-5.el6_4.x86_64.rpm pyldb-devel-1.1.25-2.el6_4.x86_64.rpm sssd-debuginfo-1.9.2-82.12.el6_4.i686.rpm sssd-debuginfo-1.9.2-82.12.el6_4.x86_64.rpm sssd-tools-1.9.2-82.12.el6_4.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 6.5): Source: libldb-1.1.25-2.el6_5.src.rpm openchange-1.0-7.el6_5.src.rpm sssd-1.9.2-129.el6_5.7.src.rpm x86_64: ldb-tools-1.1.25-2.el6_5.x86_64.rpm libipa_hbac-devel-1.9.2-129.el6_5.7.i686.rpm libipa_hbac-devel-1.9.2-129.el6_5.7.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_5.x86_64.rpm libsss_idmap-devel-1.9.2-129.el6_5.7.i686.rpm libsss_idmap-devel-1.9.2-129.el6_5.7.x86_64.rpm libsss_sudo-devel-1.9.2-129.el6_5.7.i686.rpm libsss_sudo-devel-1.9.2-129.el6_5.7.x86_64.rpm openchange-1.0-7.el6_5.x86_64.rpm openchange-client-1.0-7.el6_5.x86_64.rpm openchange-debuginfo-1.0-7.el6_5.x86_64.rpm openchange-devel-1.0-7.el6_5.x86_64.rpm openchange-devel-docs-1.0-7.el6_5.x86_64.rpm pyldb-devel-1.1.25-2.el6_5.x86_64.rpm sssd-debuginfo-1.9.2-129.el6_5.7.i686.rpm sssd-debuginfo-1.9.2-129.el6_5.7.x86_64.rpm sssd-tools-1.9.2-129.el6_5.7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.6.6): Source: openchange-1.0-7.el6_6.src.rpm i386: ldb-tools-1.1.25-2.el6_6.i686.rpm libldb-debuginfo-1.1.25-2.el6_6.i686.rpm openchange-1.0-7.el6_6.i686.rpm openchange-client-1.0-7.el6_6.i686.rpm openchange-debuginfo-1.0-7.el6_6.i686.rpm openchange-devel-1.0-7.el6_6.i686.rpm openchange-devel-docs-1.0-7.el6_6.i686.rpm pyldb-devel-1.1.25-2.el6_6.i686.rpm ppc64: ldb-tools-1.1.25-2.el6_6.ppc64.rpm libldb-debuginfo-1.1.25-2.el6_6.ppc64.rpm openchange-1.0-7.el6_6.ppc64.rpm openchange-client-1.0-7.el6_6.ppc64.rpm openchange-debuginfo-1.0-7.el6_6.ppc64.rpm openchange-devel-1.0-7.el6_6.ppc64.rpm openchange-devel-docs-1.0-7.el6_6.ppc64.rpm pyldb-devel-1.1.25-2.el6_6.ppc64.rpm s390x: ldb-tools-1.1.25-2.el6_6.s390x.rpm libldb-debuginfo-1.1.25-2.el6_6.s390x.rpm openchange-1.0-7.el6_6.s390x.rpm openchange-client-1.0-7.el6_6.s390x.rpm openchange-debuginfo-1.0-7.el6_6.s390x.rpm openchange-devel-1.0-7.el6_6.s390x.rpm openchange-devel-docs-1.0-7.el6_6.s390x.rpm pyldb-devel-1.1.25-2.el6_6.s390x.rpm x86_64: ldb-tools-1.1.25-2.el6_6.x86_64.rpm libldb-debuginfo-1.1.25-2.el6_6.x86_64.rpm openchange-1.0-7.el6_6.x86_64.rpm openchange-client-1.0-7.el6_6.x86_64.rpm openchange-debuginfo-1.0-7.el6_6.x86_64.rpm openchange-devel-1.0-7.el6_6.x86_64.rpm openchange-devel-docs-1.0-7.el6_6.x86_64.rpm pyldb-devel-1.1.25-2.el6_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2015-5370 https://access.redhat.com/security/cve/CVE-2016-2110 https://access.redhat.com/security/cve/CVE-2016-2111 https://access.redhat.com/security/cve/CVE-2016-2112 https://access.redhat.com/security/cve/CVE-2016-2113 https://access.redhat.com/security/cve/CVE-2016-2114 https://access.redhat.com/security/cve/CVE-2016-2115 https://access.redhat.com/security/cve/CVE-2016-2118 https://access.redhat.com/security/updates/classification#critical https://access.redhat.com/security/vulnerabilities/badlock https://access.redhat.com/articles/2253041 https://samba.plus https://access.redhat.com/articles/2243351 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXDWt0XlSAg2UNWIIRArsGAJ9p5AGoGq4zBzB+5A/zyjpBQHEU6QCfVEKS NrofnuCBUq+Q1qucqIpT/gE=6alT -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian releases an important patch for apache that tackles major vulnerabilities. Safeguard your servers today!. Samba4 Update, Red Hat Security, Critical Advisory, Bug Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 12, 2016 Critical Red Hat
200

Scientific Linux 6 Moderate: SLSA-2016:0449-1 Samba4 Security Update

Moderate: samba4 security update. Date: Tue, 15 Mar 2016 15:33:49 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: samba4 on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: samba4 security update Advisory ID: SLSA-2016:0449-1 Issue Date: 2016-03-15 CVE Numbers: CVE-2015-7560 -- A flaw was found in the way Samba handled ACLs on symbolic links. An authenticated user could use this flaw to gain access to an arbitrary file or directory by overwriting its ACL. (CVE-2015-7560) After installing this update, the smb service will be restarted automatically. -- SL6 x86_64 samba4-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-client-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-common-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-dc-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-dc-libs-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-debuginfo-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-devel-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-libs-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-pidl-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-python-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-swat-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-test-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-winbind-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-68.el6_7.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-68.el6_7.rc4.x86_64.rpm i386 samba4-4.0.0-68.el6_7.rc4.i686.rpm samba4-client-4.0.0-68.el6_7.rc4.i686.rpm samba4-common-4.0.0-68.el6_7.rc4.i686.rpm samba4-dc-4.0.0-68.el6_7.rc4.i686.rpm samba4-dc-libs-4.0.0-68.el6_7.rc4.i686.rpm samba4-debuginfo-4.0.0-68.el6_7.rc4.i686.rpm samba4-devel-4.0.0-68.el6_7.rc4.i686.rpm samba4-libs-4.0.0-68.el6_7.rc4.i686.rpm samba4-pidl-4.0.0-68.el6_7.rc4.i686.rpm samba4-python-4.0.0-68.el6_7.rc4.i686.rpm samba4-swat-4.0.0-68.el6_7.rc4.i686.rpm samba4-test-4.0.0-68.el6_7.rc4.i686.rpm samba4-winbind-4.0.0-68.el6_7.rc4.i686.rpm samba4-winbind-clients-4.0.0-68.el6_7.rc4.i686.rpm samba4-winbind-krb5-locator-4.0.0-68.el6_7.rc4.i686.rpm -Scientific Linux Development Team . A vulnerability in samba4 has been identified that impacts Scientific Linux systems. A patch has been released to address this security concern.. Samba4 Security Advisory, Scientific Linux Update, Access Control Fix. . LinuxSecurity.com Team

Calendar%202 Mar 15, 2016 Scientific Linux
200

Scientific Linux 6: SLSA-2016:0010-2 Moderate samba4 DoS Vulnerability

Moderate: samba4 security update. Date: Fri, 8 Jan 2016 14:32:05 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: samba4 on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: samba4 security update Advisory ID: SLSA-2016:0010-2 Issue Date: 2016-01-07 CVE Numbers: CVE-2015-5299 CVE-2015-5252 CVE-2015-5296 CVE-2015-5330 CVE-2015-7540 -- A denial of service flaw was found in the LDAP server provided by the AD DC in the Samba process daemon. A remote attacker could exploit this flaw by sending a specially crafted packet, which could cause the server to consume an excessive amount of memory and crash. (CVE-2015-7540) Multiple buffer over-read flaws were found in the way Samba handled malformed inputs in certain encodings. An authenticated, remote attacker could possibly use these flaws to disclose portions of the server memory. (CVE-2015-5330) A man-in-the-middle vulnerability was found in the way "connection signing" was implemented by Samba. A remote attacker could use this flaw to downgrade an existing Samba client connection and force the use of plain text. (CVE-2015-5296) A missing access control flaw was found in Samba. A remote, authenticated attacker could use this flaw to view the current snapshot on a Samba share, despite not having DIRECTORY_LIST access rights. (CVE-2015-5299) An access flaw was found in the way Samba verified symbolic links when creating new files on a Samba share. A remote attacker could exploit this flaw to gain access to files outside of Samba's share path. (CVE-2015-5252) After installing this update, the smb service will be restarted automatically. -- SL6 x86_64 samba4-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-client-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-common-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-dc-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-dc-libs-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-debuginfo-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-devel-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-libs-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-pidl-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-python-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-swat-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-test-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-winbind-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-67.el6_7.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-67.el6_7.rc4.x86_64.rpm i386 samba4-4.0.0-67.el6_7.rc4.i686.rpm samba4-client-4.0.0-67.el6_7.rc4.i686.rpm samba4-common-4.0.0-67.el6_7.rc4.i686.rpm samba4-dc-4.0.0-67.el6_7.rc4.i686.rpm samba4-dc-libs-4.0.0-67.el6_7.rc4.i686.rpm samba4-debuginfo-4.0.0-67.el6_7.rc4.i686.rpm samba4-devel-4.0.0-67.el6_7.rc4.i686.rpm samba4-libs-4.0.0-67.el6_7.rc4.i686.rpm samba4-pidl-4.0.0-67.el6_7.rc4.i686.rpm samba4-python-4.0.0-67.el6_7.rc4.i686.rpm samba4-swat-4.0.0-67.el6_7.rc4.i686.rpm samba4-test-4.0.0-67.el6_7.rc4.i686.rpm samba4-winbind-4.0.0-67.el6_7.rc4.i686.rpm samba4-winbind-clients-4.0.0-67.el6_7.rc4.i686.rpm samba4-winbind-krb5-locator-4.0.0-67.el6_7.rc4.i686.rpm - Scientific Linux Development Team . The recent samba4 update offers crucial enhancements to address vulnerabilities regarding denial of service and access control in Scientific Linux.. samba4 security update, Scientific Linux samba4, access issues samba4, SL6 samba update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 08, 2016 Important Scientific Linux
98

Critical Samba4 Remote Code Execution in Red Hat Enterprise Linux 6.4/6.5

Updated samba4 packages that fix one security issue are now available for Red Hat Enterprise Linux 6.4 and 6.5 Extended Update Support. Red Hat Product Security has rated this update as having Critical security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Critical: samba4 security update Advisory ID: RHSA-2015:0255-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:0255.html Issue date: 2015-02-23 CVE Names: CVE-2015-0240 ==================================================================== 1. Summary: Updated samba4 packages that fix one security issue are now available for Red Hat Enterprise Linux 6.4 and 6.5 Extended Update Support. Red Hat Product Security has rated this update as having Critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux HPC Node EUS (v. 6.4) - x86_64 Red Hat Enterprise Linux HPC Node EUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server EUS (v. 6.4) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server EUS (v. 6.5) - i386, ppc64, s390x, x86_64 3. Description: Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information. An uninitialized pointer use flaw was found in the Samba daemon (smbd). A malicious Samba client could send specially crafted netlogon packets that, when processed by smbd, could potentially lead to arbitrary code execution with the privileges of the user running smbd (by default, the root user). (CVE-2015-0240) For additional information about this flaw, see the Knowledgebase article at https://access.redhat.com/articles/1346913 Red Hat would like tothank the Samba project for reporting this issue. Upstream acknowledges Richard van Eeden of Microsoft Vulnerability Research as the original reporter of this issue. All Samba users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, the smb service will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1191325 - CVE-2015-0240 samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution 6. Package List: Red Hat Enterprise Linux HPC Node EUS (v. 6.4): Source: samba4-4.0.0-57.el6_4.rc4.src.rpm x86_64: samba4-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-client-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-common-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-dc-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-dc-libs-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-debuginfo-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-devel-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-libs-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-pidl-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-python-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-swat-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-test-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-winbind-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-57.el6_4.rc4.x86_64.rpm Red Hat Enterprise Linux HPC Node EUS (v.6.5): Source: samba4-4.0.0-65.el6_5.rc4.src.rpm x86_64: samba4-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-client-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-common-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-dc-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-dc-libs-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-debuginfo-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-devel-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-libs-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-pidl-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-python-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-swat-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-test-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-winbind-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-65.el6_5.rc4.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.6.4): Source: samba4-4.0.0-57.el6_4.rc4.src.rpm i386: samba4-4.0.0-57.el6_4.rc4.i686.rpm samba4-client-4.0.0-57.el6_4.rc4.i686.rpm samba4-common-4.0.0-57.el6_4.rc4.i686.rpm samba4-dc-4.0.0-57.el6_4.rc4.i686.rpm samba4-dc-libs-4.0.0-57.el6_4.rc4.i686.rpm samba4-debuginfo-4.0.0-57.el6_4.rc4.i686.rpm samba4-devel-4.0.0-57.el6_4.rc4.i686.rpm samba4-libs-4.0.0-57.el6_4.rc4.i686.rpm samba4-pidl-4.0.0-57.el6_4.rc4.i686.rpm samba4-python-4.0.0-57.el6_4.rc4.i686.rpm samba4-swat-4.0.0-57.el6_4.rc4.i686.rpm samba4-test-4.0.0-57.el6_4.rc4.i686.rpm samba4-winbind-4.0.0-57.el6_4.rc4.i686.rpm samba4-winbind-clients-4.0.0-57.el6_4.rc4.i686.rpm samba4-winbind-krb5-locator-4.0.0-57.el6_4.rc4.i686.rpm ppc64: samba4-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-client-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-common-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-dc-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-dc-libs-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-debuginfo-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-devel-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-libs-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-pidl-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-python-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-swat-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-test-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-winbind-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-winbind-clients-4.0.0-57.el6_4.rc4.ppc64.rpm samba4-winbind-krb5-locator-4.0.0-57.el6_4.rc4.ppc64.rpm s390x: samba4-4.0.0-57.el6_4.rc4.s390x.rpm samba4-client-4.0.0-57.el6_4.rc4.s390x.rpm samba4-common-4.0.0-57.el6_4.rc4.s390x.rpm samba4-dc-4.0.0-57.el6_4.rc4.s390x.rpm samba4-dc-libs-4.0.0-57.el6_4.rc4.s390x.rpm samba4-debuginfo-4.0.0-57.el6_4.rc4.s390x.rpm samba4-devel-4.0.0-57.el6_4.rc4.s390x.rpm samba4-libs-4.0.0-57.el6_4.rc4.s390x.rpm samba4-pidl-4.0.0-57.el6_4.rc4.s390x.rpm samba4-python-4.0.0-57.el6_4.rc4.s390x.rpm samba4-swat-4.0.0-57.el6_4.rc4.s390x.rpm samba4-test-4.0.0-57.el6_4.rc4.s390x.rpm samba4-winbind-4.0.0-57.el6_4.rc4.s390x.rpm samba4-winbind-clients-4.0.0-57.el6_4.rc4.s390x.rpm samba4-winbind-krb5-locator-4.0.0-57.el6_4.rc4.s390x.rpm x86_64: samba4-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-client-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-common-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-dc-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-dc-libs-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-debuginfo-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-devel-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-libs-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-pidl-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-python-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-swat-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-test-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-winbind-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-57.el6_4.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-57.el6_4.rc4.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.6.5): Source: samba4-4.0.0-65.el6_5.rc4.src.rpm i386: samba4-4.0.0-65.el6_5.rc4.i686.rpm samba4-client-4.0.0-65.el6_5.rc4.i686.rpm samba4-common-4.0.0-65.el6_5.rc4.i686.rpm samba4-dc-4.0.0-65.el6_5.rc4.i686.rpm samba4-dc-libs-4.0.0-65.el6_5.rc4.i686.rpm samba4-debuginfo-4.0.0-65.el6_5.rc4.i686.rpm samba4-devel-4.0.0-65.el6_5.rc4.i686.rpm samba4-libs-4.0.0-65.el6_5.rc4.i686.rpm samba4-pidl-4.0.0-65.el6_5.rc4.i686.rpm samba4-python-4.0.0-65.el6_5.rc4.i686.rpm samba4-swat-4.0.0-65.el6_5.rc4.i686.rpm samba4-test-4.0.0-65.el6_5.rc4.i686.rpm samba4-winbind-4.0.0-65.el6_5.rc4.i686.rpm samba4-winbind-clients-4.0.0-65.el6_5.rc4.i686.rpm samba4-winbind-krb5-locator-4.0.0-65.el6_5.rc4.i686.rpm ppc64: samba4-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-client-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-common-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-dc-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-dc-libs-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-debuginfo-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-devel-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-libs-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-pidl-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-python-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-swat-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-test-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-winbind-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-winbind-clients-4.0.0-65.el6_5.rc4.ppc64.rpm samba4-winbind-krb5-locator-4.0.0-65.el6_5.rc4.ppc64.rpm s390x: samba4-4.0.0-65.el6_5.rc4.s390x.rpm samba4-client-4.0.0-65.el6_5.rc4.s390x.rpm samba4-common-4.0.0-65.el6_5.rc4.s390x.rpm samba4-dc-4.0.0-65.el6_5.rc4.s390x.rpm samba4-dc-libs-4.0.0-65.el6_5.rc4.s390x.rpm samba4-debuginfo-4.0.0-65.el6_5.rc4.s390x.rpm samba4-devel-4.0.0-65.el6_5.rc4.s390x.rpm samba4-libs-4.0.0-65.el6_5.rc4.s390x.rpm samba4-pidl-4.0.0-65.el6_5.rc4.s390x.rpm samba4-python-4.0.0-65.el6_5.rc4.s390x.rpm samba4-swat-4.0.0-65.el6_5.rc4.s390x.rpm samba4-test-4.0.0-65.el6_5.rc4.s390x.rpm samba4-winbind-4.0.0-65.el6_5.rc4.s390x.rpm samba4-winbind-clients-4.0.0-65.el6_5.rc4.s390x.rpm samba4-winbind-krb5-locator-4.0.0-65.el6_5.rc4.s390x.rpm x86_64: samba4-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-client-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-common-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-dc-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-dc-libs-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-debuginfo-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-devel-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-libs-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-pidl-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-python-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-swat-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-test-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-winbind-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-65.el6_5.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-65.el6_5.rc4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0240 https://access.redhat.com/security/updates/classification/#critical https://access.redhat.com/articles/1346913 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. . Important samba4 patch for Red Hat resolves a vulnerability that could enable arbitrary code execution. Update is advised.. Red Hat Enterprise Linux,samba4 security update,critical advisory,network file sharing. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 23, 2015 Critical Red Hat
98

Red Hat 6: RHSA-2015:0260-01 High Security Fix for Samba4 Released

Updated samba4 packages that fix one security issue are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Critical security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Critical: samba4 security update Advisory ID: RHSA-2015:0250-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:0250.html Issue date: 2015-02-23 CVE Names: CVE-2015-0240 ==================================================================== 1. Summary: Updated samba4 packages that fix one security issue are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Samba is an open-source implementation of the Server Message Block (SMB) or Common Internet File System (CIFS) protocol, which allows PC-compatible machines to share files, printers, and other information. An uninitialized pointer use flaw was found in the Samba daemon (smbd). A malicious Samba client could send specially crafted netlogon packets that, when processed by smbd, could potentially lead to arbitrary code execution with the privileges of the user running smbd (by default, the root user). (CVE-2015-0240) For additional information about this flaw, see the Knowledgebase article at https://access.redhat.com/articles/1346913 Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Richard van Eeden ofMicrosoft Vulnerability Research as the original reporter of this issue. All Samba users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, the smb service will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1191325 - CVE-2015-0240 samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution 6. Package List: Red Hat Enterprise Linux Desktop (v.6): Source: samba4-4.0.0-66.el6_6.rc4.src.rpm i386: samba4-4.0.0-66.el6_6.rc4.i686.rpm samba4-client-4.0.0-66.el6_6.rc4.i686.rpm samba4-common-4.0.0-66.el6_6.rc4.i686.rpm samba4-dc-4.0.0-66.el6_6.rc4.i686.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.i686.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.i686.rpm samba4-devel-4.0.0-66.el6_6.rc4.i686.rpm samba4-libs-4.0.0-66.el6_6.rc4.i686.rpm samba4-pidl-4.0.0-66.el6_6.rc4.i686.rpm samba4-python-4.0.0-66.el6_6.rc4.i686.rpm samba4-swat-4.0.0-66.el6_6.rc4.i686.rpm samba4-test-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.i686.rpm x86_64: samba4-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-client-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-common-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-devel-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-pidl-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-python-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-swat-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-test-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.x86_64.rpm Red Hat Enterprise Linux HPC Node (v.6): Source: samba4-4.0.0-66.el6_6.rc4.src.rpm x86_64: samba4-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-client-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-common-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-devel-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-pidl-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-python-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-swat-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-test-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: samba4-4.0.0-66.el6_6.rc4.src.rpm i386: samba4-4.0.0-66.el6_6.rc4.i686.rpm samba4-client-4.0.0-66.el6_6.rc4.i686.rpm samba4-common-4.0.0-66.el6_6.rc4.i686.rpm samba4-dc-4.0.0-66.el6_6.rc4.i686.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.i686.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.i686.rpm samba4-devel-4.0.0-66.el6_6.rc4.i686.rpm samba4-libs-4.0.0-66.el6_6.rc4.i686.rpm samba4-pidl-4.0.0-66.el6_6.rc4.i686.rpm samba4-python-4.0.0-66.el6_6.rc4.i686.rpm samba4-swat-4.0.0-66.el6_6.rc4.i686.rpm samba4-test-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.i686.rpm ppc64: samba4-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-client-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-common-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-dc-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-devel-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-libs-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-pidl-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-python-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-swat-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-test-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-winbind-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.ppc64.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.ppc64.rpm s390x: samba4-4.0.0-66.el6_6.rc4.s390x.rpm samba4-client-4.0.0-66.el6_6.rc4.s390x.rpm samba4-common-4.0.0-66.el6_6.rc4.s390x.rpm samba4-dc-4.0.0-66.el6_6.rc4.s390x.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.s390x.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.s390x.rpm samba4-devel-4.0.0-66.el6_6.rc4.s390x.rpm samba4-libs-4.0.0-66.el6_6.rc4.s390x.rpm samba4-pidl-4.0.0-66.el6_6.rc4.s390x.rpm samba4-python-4.0.0-66.el6_6.rc4.s390x.rpm samba4-swat-4.0.0-66.el6_6.rc4.s390x.rpm samba4-test-4.0.0-66.el6_6.rc4.s390x.rpm samba4-winbind-4.0.0-66.el6_6.rc4.s390x.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.s390x.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.s390x.rpm x86_64: samba4-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-client-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-common-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-devel-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-pidl-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-python-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-swat-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-test-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: samba4-4.0.0-66.el6_6.rc4.src.rpm i386: samba4-4.0.0-66.el6_6.rc4.i686.rpm samba4-client-4.0.0-66.el6_6.rc4.i686.rpm samba4-common-4.0.0-66.el6_6.rc4.i686.rpm samba4-dc-4.0.0-66.el6_6.rc4.i686.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.i686.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.i686.rpm samba4-devel-4.0.0-66.el6_6.rc4.i686.rpm samba4-libs-4.0.0-66.el6_6.rc4.i686.rpm samba4-pidl-4.0.0-66.el6_6.rc4.i686.rpm samba4-python-4.0.0-66.el6_6.rc4.i686.rpm samba4-swat-4.0.0-66.el6_6.rc4.i686.rpm samba4-test-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.i686.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.i686.rpm x86_64: samba4-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-client-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-common-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-dc-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-debuginfo-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-devel-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-libs-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-pidl-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-python-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-swat-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-test-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-clients-4.0.0-66.el6_6.rc4.x86_64.rpm samba4-winbind-krb5-locator-4.0.0-66.el6_6.rc4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0240 https://access.redhat.com/security/updates/classification/#critical https://access.redhat.com/articles/1346913 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. . Important samba4 patch for Red Hat 6 addresses remote exploit vulnerability, enhancing overall system protection.. Samba4 Critical Fix, Remote Code Execution Patch, RedHat Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 23, 2015 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200