MGASA-2015-0084
Dashboard / Vulnerabilities / MGASA-2015-0084
Summary: Updated samba packages fix CVE-2015-0240
Details: Updated samba packages fix security vulnerabilities: An uninitialized pointer use flaw was found in the Samba daemon (smbd). A malicious Samba client could send specially crafted netlogon packets that, when processed by smbd, could potentially lead to arbitrary code execution with the privileges of the user running smbd (by default, the root user) (CVE-2015-0240).
References: https://advisories.mageia.org/MGASA-2015-0084.html, https://bugs.mageia.org/show_bug.cgi?id=15347, https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/, https://rhn.redhat.com/errata/RHSA-2015-0251.html
Affected packages
Package
Name: samba
Purl: pkg:rpm/mageia/samba?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
