An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for tigervnc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1666-1 Rating: critical References: #1176733 Cross-References: CVE-2020-26117 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tigervnc fixes the following issues: - CVE-2020-26117: Server certificates were stored as certiticate authorities, allowing malicious owners of these certificates to impersonate any server after a client had added an exception (bsc#1176733) This update was imported from the SUSE:SLE-15-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1666=1 Package List: - openSUSE Leap 15.2 (noarch): tigervnc-x11vnc-1.9.0-lp152.7.3.1 xorg-x11-Xvnc-java-1.9.0-lp152.7.3.1 xorg-x11-Xvnc-novnc-1.9.0-lp152.7.3.1 - openSUSE Leap 15.2 (x86_64): libXvnc-devel-1.9.0-lp152.7.3.1 libXvnc1-1.9.0-lp152.7.3.1 libXvnc1-debuginfo-1.9.0-lp152.7.3.1 tigervnc-1.9.0-lp152.7.3.1 tigervnc-debuginfo-1.9.0-lp152.7.3.1 tigervnc-debugsource-1.9.0-lp152.7.3.1 xorg-x11-Xvnc-1.9.0-lp152.7.3.1 xorg-x11-Xvnc-debuginfo-1.9.0-lp152.7.3.1 xorg-x11-Xvnc-module-1.9.0-lp152.7.3.1 xorg-x11-Xvnc-module-debuginfo-1.9.0-lp152.7.3.1 References: https://www.suse.com/security/cve/CVE-2020-26117.html https://bugzilla.suse.com/1176733 -- . An important patch for tigervnc resolves a vulnerability related to server impersonationaffecting openSUSE Leap 15.2.. openSUSE Update,tigervnc Security,server impersonation fix,critical vulnerability. . Severity: Critical. LinuxSecurity.com Team
Samba could be tricked into connecting to impersonated servers.. =========================================================================Ubuntu Security Notice USN-3092-1 September 28, 2016 samba vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Samba could be tricked into connecting to impersonated servers. Software Description: - samba: SMB/CIFS file, print, and login server for Unix Details: Stefan Metzmacher discovered that Samba incorrectly handled certain flags in SMB2/3 client connections. A remote attacker could use this issue to disable client signing and impersonate servers by performing a man in the middle attack. Samba has been updated to 4.3.11 in Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. In addition to the security fix, the updated packages contain bug fixes, new features, and possibly incompatible changes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: samba 2:4.3.11+dfsg-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: samba 2:4.3.11+dfsg-0ubuntu0.14.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3092-1 CVE-2016-2119 Package Information: https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.1 . Critical flaw in Samba for Ubuntu systems permits distant attackers to mimic servers, posing a security threat. Patch immediately!. Samba Patch, Remote Exploit, Server Impersonation, SMB/CIFS Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.